NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84790  CVE-2017-7290  SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses into outfile to create a backdoor program.    6.5  Medium  2017-04-27  2017-04-03  View
85046  CVE-2017-8101  There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.    6.8  Medium  2017-05-07  2017-04-27  View
85558  CVE-2017-8384  Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.    4.3  Medium  2017-05-27  2017-05-11  View
85814  CVE-2017-2161  FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.    2.7  Low  2017-06-12  2017-06-08  View
86070  CVE-2017-8535  The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka Microsoft Malware Protection Engine Denial of Service Vulnerability, a different vulnerability than CVE-2017-8536, CVE-2017-8537, CVE-2017-8539, and CVE-2017-8542.    4.3  Medium  2017-07-18  2017-07-07  View

Page 15921 of 17672, showing 5 records out of 88360 total, starting on record 79601, ending on 79605

Actions