NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84943  CVE-2017-7725  concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a canonical URL on installation of concrete5 using the Advanced Options settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.    4.3  Medium  2017-04-27  2017-04-20  View
84942  CVE-2017-7723  XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.    4.3  Medium  2017-06-03  2017-06-01  View
84941  CVE-2017-7722  In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with cmc and password (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.    10  High  2017-04-27  2017-04-21  View
85488  CVE-2017-7721  IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.    6.8  Medium  2017-07-18  2017-07-11  View
84940  CVE-2017-7720  Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password.    4.6  Medium  2017-05-07  2017-05-03  View

Page 230 of 17672, showing 5 records out of 88360 total, starting on record 1146, ending on 1150

Actions