NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86869 | CVE-2017-9418 | SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-17 | View | |
87125 | CVE-2017-9584 | The HBO Mobile Banking by Heritage Bank of Ozarks app 3.0.0 -- aka hbo-mobile-banking/id860224933 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 4.3 | Medium | 2017-07-18 | 2017-06-28 | View | |
87381 | CVE-2017-7458 | The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address. | 2 | 5 | Medium | 2017-07-18 | 2017-06-29 | View | |
87637 | CVE-2017-10680 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-03 | View | |
87893 | CVE-2017-2146 | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-12 | View |
Page 913 of 17672, showing 5 records out of 88360 total, starting on record 4561, ending on 4565