NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81675 | CVE-2017-5611 | SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name. | 2 | 7.5 | High | 2017-07-18 | 2017-07-17 | View | |
81674 | CVE-2017-5610 | wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
81673 | CVE-2017-5609 | SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter. | 2 | 6.5 | Medium | 2017-03-29 | 2017-03-23 | View | |
81672 | CVE-2017-5608 | Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename. | 2 | 4.3 | Medium | 2017-02-07 | 2017-02-03 | View | |
81671 | CVE-2017-5601 | An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 1338 of 17672, showing 5 records out of 88360 total, starting on record 6686, ending on 6690