NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
18996 | CVE-2016-3150 | Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-17 | View | |
19252 | CVE-2016-3445 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container, a different vulnerability than CVE-2016-5488. | 2 | 5 | Medium | 2017-01-19 | 2016-11-23 | View | |
84788 | CVE-2017-7284 | An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-20 | View | |
19508 | CVE-2016-3749 | server/LockSettingsService.java in LockSettingsService in Android 6.x before 2016-07-01 allows attackers to modify the screen-lock password or pattern via a crafted application, aka internal bug 28163930. | 2 | 4.6 | Medium | 2017-01-19 | 2016-07-11 | View | |
85044 | CVE-2017-8099 | There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. | 2 | 5.8 | Medium | 2017-05-07 | 2017-04-28 | View |
Page 1882 of 17672, showing 5 records out of 88360 total, starting on record 9406, ending on 9410