NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87339 | CVE-2017-9781 | A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html. | 2 | 4.3 | Medium | 2017-07-18 | 2017-06-29 | View | |
87380 | CVE-2017-7416 | ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated. | 2 | 4.3 | Medium | 2017-07-18 | 2017-06-29 | View | |
87381 | CVE-2017-7458 | The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address. | 2 | 5 | Medium | 2017-07-18 | 2017-06-29 | View | |
87382 | CVE-2017-7459 | ntopng before 3.0 allows HTTP Response Splitting. | 2 | 5 | Medium | 2017-07-18 | 2017-06-29 | View | |
87404 | CVE-2017-9615 | Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file. | 2 | 5 | Medium | 2017-07-18 | 2017-06-29 | View |
Page 16298 of 17672, showing 5 records out of 88360 total, starting on record 81486, ending on 81490