NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7127 | CVE-2017-5489 | Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-17 | View | |
7126 | CVE-2017-5488 | Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
7125 | CVE-2017-5487 | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
81638 | CVE-2017-5486 | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). | 2 | 7.5 | High | 2017-07-18 | 2017-06-30 | View | |
81637 | CVE-2017-5485 | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap(). | 2 | 7.5 | High | 2017-07-18 | 2017-06-30 | View |
Page 480 of 17672, showing 5 records out of 88360 total, starting on record 2396, ending on 2400