NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21318  CVE-2016-6635  Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.    6.8  Medium  2017-01-19  2016-08-23  View
86854  CVE-2016-7833  Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.    6.4  Medium  2017-06-18  2017-06-14  View
87110  CVE-2017-9569  The Citizens Bank (TX) cbtx-on-the-go/id892396102 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    4.3  Medium  2017-06-28  2017-06-27  View
87366  CVE-2017-1322  IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125918.    6.4  Medium  2017-07-18  2017-07-05  View
22342  CVE-2016-9274  Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.    4.4  Medium  2017-01-19  2016-12-05  View

Page 2538 of 17672, showing 5 records out of 88360 total, starting on record 12686, ending on 12690

Actions