NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
82225  CVE-2017-5165  An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.    6.8  Medium  2017-02-28  2017-02-16  View
82227  CVE-2017-5167  An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.    7.5  High  2017-07-18  2017-06-28  View
83500  CVE-2017-6955  An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.    Medium  2017-03-29  2017-03-21  View
82343  CVE-2016-5803  An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.          2017-02-15  2017-02-14  View
82265  CVE-2017-5963  An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the paymillToken HTTP POST parameter passed to the caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-03-18  2017-03-03  View

Page 1073 of 17672, showing 5 records out of 88360 total, starting on record 5361, ending on 5365

Actions