NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86693 | CVE-2017-9451 | Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-13 | View | |
87217 | CVE-2016-5411 | /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system. | 2017-06-18 | 2017-06-13 | View | ||||
86451 | CVE-2017-0896 | Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this. | 2 | 4 | Medium | 2017-06-17 | 2017-06-13 | View | |
87220 | CVE-2016-8219 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage applications. This could cause application downtime if the restage fails. | 2017-06-18 | 2017-06-13 | View | ||||
86709 | CVE-2017-9517 | atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-13 | View |
Page 16193 of 17672, showing 5 records out of 88360 total, starting on record 80961, ending on 80965