NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85127 | CVE-2016-1560 | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session. | 2017-04-27 | 2017-04-21 | View | ||||
84872 | CVE-2017-7581 | SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed. | 2 | 7.5 | High | 2017-04-27 | 2017-04-13 | View | |
85128 | CVE-2016-1561 | ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image. | 2017-04-27 | 2017-04-21 | View | ||||
83849 | CVE-2017-7255 | XSS exists in the CMS Made Simple (CMSMS) 2.1.6 Content-->News-->Add Article feature via the m1_title parameter. Someone must login to conduct the attack. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-04 | View | |
85129 | CVE-2016-2173 | org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. | 2017-04-27 | 2017-04-21 | View |
Page 1815 of 17672, showing 5 records out of 88360 total, starting on record 9071, ending on 9075