NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86508  CVE-2017-9303  Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.    5.8  Medium  2017-06-12  2017-06-08  View
86510  CVE-2017-9305  lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.    4.3  Medium  2017-06-12  2017-06-08  View
85743  CVE-2017-0373  The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous use lib line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.    6.8  Medium  2017-06-12  2017-06-08  View
85744  CVE-2017-0374  lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.    4.6  Medium  2017-06-12  2017-06-08  View
81916  CVE-2016-8941  IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.    6.8  Medium  2017-06-12  2017-06-08  View

Page 16166 of 17672, showing 5 records out of 88360 total, starting on record 80826, ending on 80830

Actions