NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 21257 | CVE-2016-6496 | The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. | 2 | 7.5 | High | 2017-01-19 | 2016-12-14 | View | |
| 24329 | CVE-2015-2213 | SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
| 24585 | CVE-2015-2563 | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. NOTE: The cat parameter vector is already covered by CVE-2008-4157. | 2 | 7.5 | High | 2017-01-19 | 2015-03-23 | View | |
| 27657 | CVE-2015-6835 | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content. | 2 | 7.5 | High | 2017-01-19 | 2016-11-29 | View | |
| 28681 | CVE-2015-8562 | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View |
Page 2040 of 17672, showing 5 records out of 88360 total, starting on record 10196, ending on 10200