NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
7125  CVE-2017-5487  wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.    Medium  2017-07-18  2017-07-17  View
7124  CVE-2017-5480  Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter.    5.5  Medium  2017-01-19  2017-01-18  View
7123  CVE-2017-5476  Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.    6.8  Medium  2017-01-30  2017-01-25  View
7122  CVE-2017-5475  comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.    6.8  Medium  2017-01-30  2017-01-25  View
7121  CVE-2017-5474  Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.    5.8  Medium  2017-01-30  2017-01-25  View

Page 16248 of 17672, showing 5 records out of 88360 total, starting on record 81236, ending on 81240

Actions