NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31730 | CVE-2014-3552 | The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction. | 2 | 6 | Medium | 2017-01-19 | 2014-07-29 | View | |
31986 | CVE-2014-3899 | Gretech GOM Player 2.2.51.5149 and earlier allows remote attackers to cause a denial of service (launch outage) via a crafted image file. | 2 | 4.3 | Medium | 2017-01-19 | 2014-08-12 | View | |
32242 | CVE-2014-4226 | Unspecified vulnerability in the PeopleSoft Enterprise FIN Install component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | 2 | 5.1 | Medium | 2017-01-19 | 2017-01-06 | View | |
32498 | CVE-2014-4517 | Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the searchString parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-01-07 | View | |
32754 | CVE-2014-4852 | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-19 | 2014-07-10 | View |
Page 16863 of 17672, showing 5 records out of 88360 total, starting on record 84311, ending on 84315