NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87309 | CVE-2017-9730 | SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter. | 2 | 7.5 | High | 2017-06-28 | 2017-06-23 | View | |
22029 | CVE-2016-8291 | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Application Platform. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
22285 | CVE-2016-9137 | Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing. | 2 | 7.5 | High | 2017-01-19 | 2017-01-10 | View | |
87821 | CVE-2017-11195 | Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
22541 | CVE-2016-9997 | SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View |
Page 917 of 17672, showing 5 records out of 88360 total, starting on record 4581, ending on 4585