NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22283 | CVE-2016-9135 | Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version parameter. Impact is Information Disclosure. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
87819 | CVE-2017-11193 | Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker to run these commands against any IP if they can get an admin to visit their malicious CSRF page. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-17 | View | |
22539 | CVE-2016-9966 | Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a possible DoS attack, or possibly gain privileges. The Samsung ID is SVE-2016-7120. | 2 | 10 | High | 2017-01-19 | 2016-12-22 | View | |
88075 | CVE-2017-7317 | An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin. | 2 | 10 | High | 2017-07-18 | 2017-07-07 | View | |
22795 | CVE-2015-0317 | Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0319. | 2 | 10 | High | 2017-01-19 | 2015-02-20 | View |
Page 782 of 17672, showing 5 records out of 88360 total, starting on record 3906, ending on 3910