NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35670 | CVE-2014-8682 | Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go. | 2 | 7.5 | High | 2017-01-19 | 2014-11-24 | View | |
| 38742 | CVE-2013-2827 | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value. | 2 | 7.5 | High | 2017-01-18 | 2014-01-16 | View | |
| 40534 | CVE-2013-5117 | SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. | 2 | 7.5 | High | 2017-01-18 | 2014-03-13 | View | |
| 41302 | CVE-2013-6172 | steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code. | 2 | 7.5 | High | 2017-01-18 | 2014-03-26 | View | |
| 44118 | CVE-2012-2303 | The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module. | 2 | 7.5 | High | 2017-01-19 | 2012-08-09 | View |
Page 2913 of 17672, showing 5 records out of 88360 total, starting on record 14561, ending on 14565