NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86869  CVE-2017-9418  SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.    6.5  Medium  2017-07-18  2017-07-17  View
87125  CVE-2017-9584  The HBO Mobile Banking by Heritage Bank of Ozarks app 3.0.0 -- aka hbo-mobile-banking/id860224933 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    4.3  Medium  2017-07-18  2017-06-28  View
87381  CVE-2017-7458  The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.    Medium  2017-07-18  2017-06-29  View
87637  CVE-2017-10680  Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.    6.8  Medium  2017-07-18  2017-07-03  View
87893  CVE-2017-2146  Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.    3.5  Low  2017-07-18  2017-07-12  View

Page 913 of 17672, showing 5 records out of 88360 total, starting on record 4561, ending on 4565

Actions