NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88319 | CVE-2016-8953 | IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118840. | 2017-07-18 | 2017-07-17 | View | ||||
23551 | CVE-2015-1172 | Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 and earlier for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory. | 2 | 7.5 | High | 2017-07-18 | 2017-07-17 | View | |
87811 | CVE-2017-11179 | FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-16 | View | |
87812 | CVE-2017-11180 | FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-16 | View | |
87823 | CVE-2017-11198 | Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-16 | View |
Page 120 of 17672, showing 5 records out of 88360 total, starting on record 596, ending on 600