NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15426 | CVE-2010-4121 | ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only." | 2 | 7.5 | High | 2017-01-18 | 2010-10-29 | View | |
| 16194 | CVE-2010-4959 | SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter. | 2 | 7.5 | High | 2017-01-18 | 2012-02-13 | View | |
| 17986 | CVE-2016-1636 | The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache information about integrity-check occurrences instead of integrity-check successes, which allows remote attackers to bypass the Subresource Integrity (aka SRI) protection mechanism by triggering two loads of the same resource. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
| 84802 | CVE-2017-7324 | setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter. | 2 | 7.5 | High | 2017-04-27 | 2017-03-31 | View | |
| 20034 | CVE-2016-4357 | HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2028. | 2 | 7.5 | High | 2017-01-19 | 2016-08-23 | View |
Page 2685 of 17672, showing 5 records out of 88360 total, starting on record 13421, ending on 13425