NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84863 | CVE-2017-7570 | PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-13 | View | |
84862 | CVE-2017-7569 | In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037. | 2 | 5 | Medium | 2017-04-27 | 2017-04-12 | View | |
84861 | CVE-2017-7566 | MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism. | 2 | 4 | Medium | 2017-04-27 | 2017-04-13 | View | |
84860 | CVE-2017-7565 | Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-12 | View | |
86638 | CVE-2017-7564 | In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers. | 2 | 5 | Medium | 2017-06-17 | 2017-06-15 | View |
Page 252 of 17672, showing 5 records out of 88360 total, starting on record 1256, ending on 1260