NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84786 | CVE-2017-7282 | An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI). | 2 | 7.1 | High | 2017-04-27 | 2017-04-24 | View | |
85042 | CVE-2017-8085 | In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php. | 2 | 4.3 | Medium | 2017-05-07 | 2017-04-28 | View | |
85554 | CVE-2017-8376 | GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-10 | View | |
85810 | CVE-2017-1320 | IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125732. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-07 | View | |
86066 | CVE-2017-8360 | Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:UsersPublicMicTray.log by any process. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-07 | View |
Page 642 of 17672, showing 5 records out of 88360 total, starting on record 3206, ending on 3210