NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 87310 | CVE-2017-9741 | install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file. | 2 | 7.5 | High | 2017-07-18 | 2017-06-29 | View | |
| 22286 | CVE-2016-9138 | PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup. | 2 | 7.5 | High | 2017-01-19 | 2017-01-06 | View | |
| 24078 | CVE-2015-1867 | Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
| 27918 | CVE-2015-7235 | Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data action in a request to the default URI. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View | |
| 32014 | CVE-2014-3935 | SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter. | 2 | 7.5 | High | 2017-01-19 | 2014-06-03 | View |
Page 2101 of 17672, showing 5 records out of 88360 total, starting on record 10501, ending on 10505