NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 21825 | CVE-2016-7401 | The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies. | 2 | 5 | Medium | 2017-01-19 | 2016-10-04 | View | |
| 22337 | CVE-2016-9242 | Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-29 | View | |
| 88129 | CVE-2017-8387 | STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-14 | View | |
| 22849 | CVE-2015-0371 | Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity and availability via unknown vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2016-06-29 | View | |
| 23361 | CVE-2015-0950 | Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-04-06 | View |
Page 2356 of 17672, showing 5 records out of 88360 total, starting on record 11776, ending on 11780