CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102765  CVE-2017-5945  Candidate  An issue was discovered in the PoodLL Filter plugin through 3.0.20 for Moodle. The vulnerability exists due to insufficient filtration of user-supplied data in the "poodll_audio_url" HTTP GET parameter passed to the "filter_poodll_moodle32_2016112802/poodll/mp3recorderskins/brazil/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170209)  None (candidate not yet proposed)    View
102764  CVE-2017-5944  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170209)  None (candidate not yet proposed)    View
102763  CVE-2017-5943  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170209)  None (candidate not yet proposed)    View
102762  CVE-2017-5942  Candidate  An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail.  Assigned (20170209)  None (candidate not yet proposed)    View
102761  CVE-2017-5941  Candidate  An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).  Assigned (20170209)  None (candidate not yet proposed)    View

Page 391 of 20943, showing 5 records out of 104715 total, starting on record 1951, ending on 1955

Actions