NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21825  CVE-2016-7401  The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.    Medium  2017-01-19  2016-10-04  View
22337  CVE-2016-9242  Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter.    6.5  Medium  2017-01-19  2016-11-29  View
88129  CVE-2017-8387  STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands.    4.3  Medium  2017-07-18  2017-07-14  View
22849  CVE-2015-0371  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity and availability via unknown vectors.    4.9  Medium  2017-01-19  2016-06-29  View
23361  CVE-2015-0950  Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter.    4.3  Medium  2017-01-19  2015-04-06  View

Page 2356 of 17672, showing 5 records out of 88360 total, starting on record 11776, ending on 11780

Actions