NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18553 | CVE-2016-2308 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, which allows remote attackers to obtain sensitive information by reading a file. | 2 | 7.5 | High | 2017-01-19 | 2016-10-05 | View | |
| 84857 | CVE-2017-7462 | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | 2 | 7.5 | High | 2017-04-27 | 2017-04-18 | View | |
| 86649 | CVE-2017-8835 | SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database. | 2 | 7.5 | High | 2017-06-17 | 2017-06-12 | View | |
| 31097 | CVE-2014-2752 | SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2014-06-18 | View | |
| 33145 | CVE-2014-5520 | SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php. | 2 | 7.5 | High | 2017-01-19 | 2014-10-30 | View |
Page 3336 of 17672, showing 5 records out of 88360 total, starting on record 16676, ending on 16680