CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102430  CVE-2017-5610  Candidate  wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.  Assigned (20170128)  None (candidate not yet proposed)    View
102429  CVE-2017-5609  Candidate  SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.  Assigned (20170128)  None (candidate not yet proposed)    View
102428  CVE-2017-5608  Candidate  Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename.  Assigned (20170128)  None (candidate not yet proposed)    View
102427  CVE-2017-5607  Candidate  Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.  Assigned (20170128)  None (candidate not yet proposed)    View
102426  CVE-2017-5606  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Xabber (only if manually enabled: 1.0.30, 1.0.30 VIP, beta 1.0.3 - 1.0.74; Android).  Assigned (20170128)  None (candidate not yet proposed)    View

Page 458 of 20943, showing 5 records out of 104715 total, starting on record 2286, ending on 2290

Actions