NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87795  CVE-2017-11143  In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.    Medium  2017-07-18  2017-07-17  View
88307  CVE-2016-4996  discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.          2017-07-18  2017-07-17  View
88308  CVE-2016-6019  IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739.          2017-07-18  2017-07-17  View
25588  CVE-2015-4038  The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.    6.5  Medium  2017-07-18  2017-07-17  View
87541  CVE-2017-1000001  FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.          2017-07-18  2017-07-17  View

Page 17660 of 17672, showing 5 records out of 88360 total, starting on record 88296, ending on 88300

Actions