NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87402  CVE-2017-9466  The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router configuration service tddp via the LAN and Ath0 (Wi-Fi) interfaces.    7.5  High  2017-07-18  2017-07-06  View
24938  CVE-2015-2993  SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.    7.5  High  2017-01-19  2016-12-30  View
35434  CVE-2014-8363  SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.    7.5  High  2017-01-19  2014-10-24  View
35946  CVE-2014-9195  Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.    7.5  High  2017-01-19  2015-01-22  View
36202  CVE-2014-9519  SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter.    7.5  High  2017-01-19  2015-01-06  View

Page 3157 of 17672, showing 5 records out of 88360 total, starting on record 15781, ending on 15785

Actions