NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86868  CVE-2016-9991  IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.    Medium  2017-06-18  2017-06-14  View
87124  CVE-2017-9583  The Charlevoix State Bank by Charlevoix State Bank app 3.0.1 -- aka charlevoix-state-bank/id1128963717 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    4.3  Medium  2017-07-18  2017-06-28  View
87380  CVE-2017-7416  ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.    4.3  Medium  2017-07-18  2017-06-29  View
87636  CVE-2017-10679  Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.    Medium  2017-07-18  2017-07-05  View
87892  CVE-2017-2145  Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.    5.8  Medium  2017-07-18  2017-07-14  View

Page 905 of 17672, showing 5 records out of 88360 total, starting on record 4521, ending on 4525

Actions