NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31990  CVE-2014-3903  Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via crafted Exif data.    3.5  Low  2017-07-18  2017-07-17  View
87543  CVE-2017-1000003  ATutor versions 2.2.1 and earlier are vulnerable to a incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to a incorrect access control check vulnerability in the Module component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to a incorrect access control check vulnerability in the Alternative Content component resulting in privilege escalation.          2017-07-18  2017-07-17  View
88311  CVE-2016-6793  The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.7 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.          2017-07-18  2017-07-17  View
87544  CVE-2017-1000004  ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Assignment Dropbox component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and older are vulnerable to a SQL injection in the BasicLTI component resulting in information disclosure, database modification or potential code execution. ATutor version 2.2.1 and older is vulnerable to a SQL injection vulnerability in the Blog Post component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Blog component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection in the Group Course Email component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Course Alumni component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Course Enrolment component resulting in information disclosure, database modification or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Group Membership component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Course unenrolment component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL Injection vulnerability in the Course Enrolment List Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Glossary component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection in the Social Group Member Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Social Friend Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Social Group Search component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the File Comment component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Gradebook Test Title component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the User Group Membership component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Inbox/Sent Items component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL injection vulnerability in the Sent Messages component resulting in information disclosure, database modification, or potential code execution. ATutor versions 2.2.1 and earlier are vulnerable to a SQL in          2017-07-18  2017-07-17  View
87800  CVE-2017-11163  Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.    3.5  Low  2017-07-18  2017-07-17  View

Page 17662 of 17672, showing 5 records out of 88360 total, starting on record 88306, ending on 88310

Actions