NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 85941 | CVE-2017-5965 | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a .. in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-08 | View | |
| 20661 | CVE-2016-5392 | The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list. | 2 | 6.8 | Medium | 2017-01-19 | 2016-08-05 | View | |
| 20917 | CVE-2016-5715 | Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6501. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-17 | View | |
| 21173 | CVE-2016-6398 | The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from earlier network communication by reading packet data, aka Bug ID CSCvb16274. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 86709 | CVE-2017-9517 | atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-13 | View |
Page 15034 of 17672, showing 5 records out of 88360 total, starting on record 75166, ending on 75170