NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40933 | CVE-2013-5674 | badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter. | 2 | 7.5 | High | 2017-01-18 | 2013-09-25 | View | |
| 41189 | CVE-2013-5977 | Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php. | 2 | 6.8 | Medium | 2017-01-18 | 2013-11-20 | View | |
| 41445 | CVE-2013-6386 | Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack. | 2 | 6.8 | Medium | 2017-01-18 | 2014-01-13 | View | |
| 41701 | CVE-2013-6822 | GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue. | 2 | 10 | High | 2017-01-18 | 2013-11-20 | View | |
| 41957 | CVE-2013-7196 | static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication. | 2 | 5.5 | Medium | 2017-01-18 | 2014-04-21 | View |
Page 15886 of 17672, showing 5 records out of 88360 total, starting on record 79426, ending on 79430