NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 30530 | CVE-2014-2024 | Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/. | 2 | 4.3 | Medium | 2017-01-19 | 2014-03-25 | View | |
| 30786 | CVE-2014-2356 | Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request. | 2 | 5 | Medium | 2017-01-19 | 2014-08-04 | View | |
| 31042 | CVE-2014-2655 | SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias. | 2 | 6.5 | Medium | 2017-01-19 | 2014-06-05 | View | |
| 31298 | CVE-2014-3021 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method. | 2 | 5 | Medium | 2017-01-19 | 2014-10-21 | View | |
| 31554 | CVE-2014-3352 | Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh84801. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 2397 of 17672, showing 5 records out of 88360 total, starting on record 11981, ending on 11985