NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35845 | CVE-2014-9024 | The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path. | 2 | 7.5 | High | 2017-01-19 | 2014-11-20 | View | |
36101 | CVE-2014-9394 | Multiple cross-site request forgery (CSRF) vulnerabilities in the PWGRandom plugin 1.11 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) pwgrandom_title or (2) pwgrandom_category parameter in the pwgrandom page to wp-admin/options-general.php. | 2 | 6.8 | Medium | 2017-01-19 | 2015-01-12 | View | |
36357 | CVE-2014-9773 | modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks. | 2 | 5 | Medium | 2017-01-19 | 2016-06-15 | View | |
36613 | CVE-2013-0258 | The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username. | 2 | 6.8 | Medium | 2017-01-18 | 2013-04-05 | View | |
36869 | CVE-2013-0544 | Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors. | 2 | 5.5 | Medium | 2017-01-18 | 2013-04-24 | View |
Page 385 of 17672, showing 5 records out of 88360 total, starting on record 1921, ending on 1925