NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86193  CVE-2017-9069  In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.    6.5  Medium  2017-06-03  2017-05-30  View
86192  CVE-2017-9068  In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.    4.3  Medium  2017-06-03  2017-05-30  View
86191  CVE-2017-9067  In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.    4.4  Medium  2017-06-03  2017-05-31  View
86190  CVE-2017-9066  In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.    Medium  2017-07-18  2017-07-17  View
86189  CVE-2017-9065  In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.    Medium  2017-07-18  2017-07-17  View

Page 106 of 17672, showing 5 records out of 88360 total, starting on record 526, ending on 530

Actions