NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84909  CVE-2017-7621  Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.    4.3  Medium  2017-04-27  2017-04-17  View
84910  CVE-2017-7622  dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arguments to make a backdoor or privilege escalation, by calling DoWriteGrubSettings() provided by dde-daemon.    High  2017-04-27  2017-04-17  View
84913  CVE-2017-7625  In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to /dapur/apps/app_theme/libs/save_file.php and then execute code.    7.5  High  2017-04-27  2017-04-17  View
84919  CVE-2017-7646  SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.    Medium  2017-04-27  2017-04-17  View
84920  CVE-2017-7647  SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.    6.5  Medium  2017-04-27  2017-04-17  View

Page 15847 of 17672, showing 5 records out of 88360 total, starting on record 79231, ending on 79235

Actions