NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86322  CVE-2014-0225  When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.    6.8  Medium  2017-06-12  2017-06-07  View
86578  CVE-2017-1196  IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.    Medium  2017-06-17  2017-06-14  View
21298  CVE-2016-6614  An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.    4.3  Medium  2017-01-19  2016-12-14  View
86834  CVE-2016-7808  Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-06-18  2017-06-15  View
87090  CVE-2017-9419  Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.    4.3  Medium  2017-07-18  2017-07-17  View

Page 1813 of 17672, showing 5 records out of 88360 total, starting on record 9061, ending on 9065

Actions