NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22306  CVE-2016-9183  In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of " or " characters. Impact is Information Disclosure.    Medium  2017-01-19  2016-11-29  View
22562  CVE-2015-0022  Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.    9.3  High  2017-01-19  2015-09-01  View
88098  CVE-2017-7726  iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.    Medium  2017-07-18  2017-07-13  View
22818  CVE-2015-0340  Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass intended file-upload restrictions via unspecified vectors.    Medium  2017-01-19  2015-03-23  View
88354  CVE-2016-8032  Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.    4.4  Medium  2017-07-18  2017-07-11  View

Page 2341 of 17672, showing 5 records out of 88360 total, starting on record 11701, ending on 11705

Actions