NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84765 | CVE-2017-6973 | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-11 | View | |
84764 | CVE-2017-6968 | GMV Checker ATM Security prior to 5.0.18 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka PT-2017-03. | 2 | 9 | High | 2017-04-27 | 2017-04-11 | View | |
84763 | CVE-2017-6956 | On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition Information Element (FT-IE). | 2 | 8.3 | High | 2017-04-27 | 2017-04-11 | View | |
84762 | CVE-2017-6919 | Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests. | 2 | 6 | Medium | 2017-07-18 | 2017-07-10 | View | |
84761 | CVE-2017-6884 | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | 2 | 9 | High | 2017-04-27 | 2017-04-12 | View |
Page 720 of 17672, showing 5 records out of 88360 total, starting on record 3596, ending on 3600