NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84786  CVE-2017-7282  An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).    7.1  High  2017-04-27  2017-04-24  View
85042  CVE-2017-8085  In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.    4.3  Medium  2017-05-07  2017-04-28  View
85554  CVE-2017-8376  GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.    3.5  Low  2017-05-27  2017-05-10  View
85810  CVE-2017-1320  IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125732.    3.5  Low  2017-07-18  2017-07-07  View
86066  CVE-2017-8360  Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:UsersPublicMicTray.log by any process.    2.1  Low  2017-07-18  2017-07-07  View

Page 642 of 17672, showing 5 records out of 88360 total, starting on record 3206, ending on 3210

Actions