NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 17219 | CVE-2016-0862 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 17475 | CVE-2016-10148 | The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896. | 2 | 4 | Medium | 2017-03-18 | 2017-03-15 | View | |
| 17731 | CVE-2016-1317 | Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098. | 2 | 4 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 86339 | CVE-2015-5382 | program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard. | 2 | 4 | Medium | 2017-06-04 | 2017-05-31 | View | |
| 88131 | CVE-2017-8442 | Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and passphrases of SSL keys that were configured as part of an authentication realm. This could allow an authenticated Elasticsearch user to improperly view these details. | 2 | 4 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 14467 of 17672, showing 5 records out of 88360 total, starting on record 72331, ending on 72335