NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
32558 | CVE-2014-4593 | Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filter parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-10 | View | |
32814 | CVE-2014-4942 | The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function. | 2 | 5 | Medium | 2017-01-19 | 2014-07-14 | View | |
33070 | CVE-2014-5387 | Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php. | 2 | 6.5 | Medium | 2017-01-19 | 2015-09-08 | View | |
33326 | CVE-2014-5702 | The Penguin Run (aka com.skyboard.google.penguinRun) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.4 | Medium | 2017-01-19 | 2014-09-11 | View | |
33582 | CVE-2014-5957 | The Alien War Survivors (aka com.ly.a13.gp) application 1.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.4 | Medium | 2017-01-19 | 2014-09-23 | View |
Page 1680 of 17672, showing 5 records out of 88360 total, starting on record 8396, ending on 8400