NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83967  CVE-2016-5758  A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.    6.8  Medium  2017-03-29  2017-03-24  View
87339  CVE-2017-9781  A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, which is returned unencoded with content type text/html.    4.3  Medium  2017-07-18  2017-06-29  View
21228  CVE-2016-6454  A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected Releases: 11.5(1). Known Fixed Releases: 11.5(0.98000.216).    4.3  Medium  2017-01-19  2016-11-28  View
88016  CVE-2017-6038  A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.    5.8  Medium  2017-07-18  2017-07-03  View
83954  CVE-2016-4504  A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB"log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.    6.8  Medium  2017-03-29  2017-03-24  View

Page 369 of 17672, showing 5 records out of 88360 total, starting on record 1841, ending on 1845

Actions