NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 22351 | CVE-2016-9287 | In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter "$term" used directly in SQL. Impact is a SQL injection. | 2 | 7.5 | High | 2017-01-19 | 2016-11-29 | View | |
| 24911 | CVE-2015-2962 | CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2016-12-02 | View | |
| 27983 | CVE-2015-7369 | The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2015-10-15 | View | |
| 29519 | CVE-2014-0635 | Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2014-04-01 | View | |
| 30287 | CVE-2014-1711 | The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors. | 2 | 7.5 | High | 2017-01-19 | 2014-03-25 | View |
Page 2831 of 17672, showing 5 records out of 88360 total, starting on record 14151, ending on 14155