NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 87402 | CVE-2017-9466 | The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router configuration service tddp via the LAN and Ath0 (Wi-Fi) interfaces. | 2 | 7.5 | High | 2017-07-18 | 2017-07-06 | View | |
| 24938 | CVE-2015-2993 | SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
| 35434 | CVE-2014-8363 | SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter. | 2 | 7.5 | High | 2017-01-19 | 2014-10-24 | View | |
| 35946 | CVE-2014-9195 | Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic. | 2 | 7.5 | High | 2017-01-19 | 2015-01-22 | View | |
| 36202 | CVE-2014-9519 | SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter. | 2 | 7.5 | High | 2017-01-19 | 2015-01-06 | View |
Page 3157 of 17672, showing 5 records out of 88360 total, starting on record 15781, ending on 15785