NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86691 | CVE-2017-9448 | Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in coreadminajaxpagessave-revision.php and coreadminmodulespages evisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-12 | View | |
86947 | CVE-2017-6659 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCvc91800. Known Affected Releases: 11.5(0) 11.6. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
87203 | CVE-2016-10338 | In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing. | 2 | 9.3 | High | 2017-06-23 | 2017-06-19 | View | |
87459 | CVE-2015-3315 | Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to librpm. | 2017-06-28 | 2017-06-27 | View | ||||
87715 | CVE-2017-10796 | On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL. | 2017-07-18 | 2017-07-02 | View |
Page 16734 of 17672, showing 5 records out of 88360 total, starting on record 83666, ending on 83670