NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84839 | CVE-2017-7410 | Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-11 | View | |
85607 | CVE-2015-8257 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml. | 2017-05-08 | 2017-05-02 | View | ||||
85863 | CVE-2017-2535 | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the Security component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (resource consumption) via a crafted app. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
86119 | CVE-2017-8898 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the <> Source option. | 2 | 7.5 | High | 2017-05-27 | 2017-05-16 | View | |
86375 | CVE-2016-7977 | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document. | 2 | 4.3 | Medium | 2017-06-04 | 2017-06-01 | View |
Page 1040 of 17672, showing 5 records out of 88360 total, starting on record 5196, ending on 5200