NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39957 | CVE-2013-4338 | wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations. | 2 | 7.5 | High | 2017-01-18 | 2013-10-02 | View | |
40213 | CVE-2013-4650 | MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database. | 2 | 6.5 | Medium | 2017-01-18 | 2013-07-05 | View | |
40469 | CVE-2013-4999 | phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php. | 2 | 5 | Medium | 2017-01-18 | 2013-07-31 | View | |
40725 | CVE-2013-5427 | Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-18 | 2014-02-04 | View | |
40981 | CVE-2013-5749 | Cross-site scripting (XSS) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to inject arbitrary web script or HTML via the new_project parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2014-05-13 | View |
Page 1825 of 17672, showing 5 records out of 88360 total, starting on record 9121, ending on 9125