NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86119  CVE-2017-8898  Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the <> Source option.    7.5  High  2017-05-27  2017-05-16  View
21095  CVE-2016-6288  The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.    7.5  High  2017-01-19  2016-09-26  View
87143  CVE-2017-9602  KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.    7.5  High  2017-07-18  2017-07-05  View
22375  CVE-2016-9427  Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.    7.5  High  2017-01-19  2017-01-06  View
23399  CVE-2015-1000003  Blind SQL Injection in filedownload v1.4 wordpress plugin    7.5  High  2017-03-29  2017-03-28  View

Page 3117 of 17672, showing 5 records out of 88360 total, starting on record 15581, ending on 15585

Actions