NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28182 | CVE-2015-7695 | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 35350 | CVE-2014-8138 | Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file. | 2 | 7.5 | High | 2017-01-19 | 2016-12-06 | View | |
| 37910 | CVE-2013-1756 | The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. | 2 | 7.5 | High | 2017-01-18 | 2014-06-13 | View | |
| 38678 | CVE-2013-2741 | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request. | 2 | 7.5 | High | 2017-01-18 | 2013-04-02 | View | |
| 39958 | CVE-2013-4339 | WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string. | 2 | 7.5 | High | 2017-01-18 | 2013-12-30 | View |
Page 2193 of 17672, showing 5 records out of 88360 total, starting on record 10961, ending on 10965