NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27037 | CVE-2015-6004 | Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 27036 | CVE-2015-6003 | Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account. | 2 | 9.3 | High | 2017-01-19 | 2016-12-07 | View | |
| 27035 | CVE-2015-5999 | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27034 | CVE-2015-5998 | Impero Education Pro before 5105 relies on the -1|AUTHENTICATEx02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command. | 2 | 10 | High | 2017-01-19 | 2015-09-16 | View | |
| 27033 | CVE-2015-5997 | Impero Education Pro before 5105 uses a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro string, which makes it easier for remote attackers to obtain plaintext data by sniffing the network for ciphertext data. | 2 | 7.8 | High | 2017-01-19 | 2015-09-16 | View |
Page 2946 of 17672, showing 5 records out of 88360 total, starting on record 14726, ending on 14730