NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86342 | CVE-2015-5468 | Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php. | 2 | 5 | Medium | 2017-06-04 | 2017-06-01 | View | |
86598 | CVE-2017-2209 | Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation) (The versions which were available on the website prior to 2017 April 4) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 2 | 6.8 | Medium | 2017-06-23 | 2017-06-22 | View | |
86854 | CVE-2016-7833 | Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors. | 2 | 6.4 | Medium | 2017-06-18 | 2017-06-14 | View | |
87110 | CVE-2017-9569 | The Citizens Bank (TX) cbtx-on-the-go/id892396102 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 4.3 | Medium | 2017-06-28 | 2017-06-27 | View | |
87366 | CVE-2017-1322 | IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125918. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-05 | View |
Page 16046 of 17672, showing 5 records out of 88360 total, starting on record 80226, ending on 80230