NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22351  CVE-2016-9287  In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter "$term" used directly in SQL. Impact is a SQL injection.    7.5  High  2017-01-19  2016-11-29  View
24911  CVE-2015-2962  CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vectors.    7.5  High  2017-01-19  2016-12-02  View
27983  CVE-2015-7369  The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.    7.5  High  2017-01-19  2015-10-15  View
29519  CVE-2014-0635  Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.    7.5  High  2017-01-19  2014-04-01  View
30287  CVE-2014-1711  The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.    7.5  High  2017-01-19  2014-03-25  View

Page 2831 of 17672, showing 5 records out of 88360 total, starting on record 14151, ending on 14155

Actions