NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86508  CVE-2017-9303  Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.    5.8  Medium  2017-06-12  2017-06-08  View
86509  CVE-2017-9304  libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function.    Medium  2017-06-12  2017-06-06  View
86510  CVE-2017-9305  lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.    4.3  Medium  2017-06-12  2017-06-08  View
86511  CVE-2017-9306  inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an <svg/onload= substring instead of an <svg onload= substring.    4.3  Medium  2017-06-12  2017-06-09  View
86512  CVE-2017-9307  SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.    Medium  2017-06-12  2017-06-09  View

Page 17602 of 17672, showing 5 records out of 88360 total, starting on record 88006, ending on 88010

Actions