NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28182  CVE-2015-7695  The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.    7.5  High  2017-01-19  2016-11-28  View
35350  CVE-2014-8138  Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.    7.5  High  2017-01-19  2016-12-06  View
37910  CVE-2013-1756  The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.    7.5  High  2017-01-18  2014-06-13  View
38678  CVE-2013-2741  importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.    7.5  High  2017-01-18  2013-04-02  View
39958  CVE-2013-4339  WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.    7.5  High  2017-01-18  2013-12-30  View

Page 2193 of 17672, showing 5 records out of 88360 total, starting on record 10961, ending on 10965

Actions