Latest CVE Feed
-
5.7
MEDIUMCVE-2024-44072
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an ar... Read more
Affected Products :- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
5.7
MEDIUMCVE-2024-34545
Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.7
MEDIUMCVE-2024-5170
The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability i... Read more
Affected Products : logo_manager_for_enamad- Published: Sep. 17, 2024
- Modified: Sep. 27, 2024
-
5.7
MEDIUMCVE-2016-9719
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulne... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2021-23284
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastruc... Read more
- Published: Apr. 18, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2017-6775
A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, local attacker to elevate their privileges to admin-level privileges. The vulnerability is due to incor... Read more
Affected Products : asr_5000_software- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2022-31076
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message can crash CloudCore by triggering a nil-pointer dereference in the UDS Server... Read more
Affected Products : kubeedge- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-43959
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of J... Read more
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-47688
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2020-27269
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate a... Read more
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-6015
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.... Read more
Affected Products : vault- Published: Aug. 01, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authentication
-
5.7
MEDIUMCVE-2021-31222
SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.... Read more
Affected Products : endpoint_security- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-22784
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.... Read more
Affected Products : c-bus_toolkit- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2020-19268
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.... Read more
Affected Products : dswjcms- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-36285
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a bru... Read more
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-35203
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.... Read more
Affected Products : ngeniusone- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-35601
Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Students Administration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with... Read more
Affected Products : peoplesoft_enterprise_cs_sa_integration_pack- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-25501
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.... Read more
- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-8790
Huawei CloudEngine 5800 with software before V200R001C00SPC700, CloudEngine 6800 with software before V200R001C00SPC700, CloudEngine 7800 with software before V200R001C00SPC700, CloudEngine 8800 with software before V200R001C00SPC700, CloudEngine 12800 wi... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2018-5448
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.... Read more
- Published: May. 04, 2018
- Modified: May. 22, 2025