NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
18553  CVE-2016-2308  American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, which allows remote attackers to obtain sensitive information by reading a file.    7.5  High  2017-01-19  2016-10-05  View
84857  CVE-2017-7462  Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.    7.5  High  2017-04-27  2017-04-18  View
86649  CVE-2017-8835  SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.    7.5  High  2017-06-17  2017-06-12  View
31097  CVE-2014-2752  SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.    7.5  High  2017-01-19  2014-06-18  View
33145  CVE-2014-5520  SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php.    7.5  High  2017-01-19  2014-10-30  View

Page 3336 of 17672, showing 5 records out of 88360 total, starting on record 16676, ending on 16680

Actions