Latest CVE Feed
-
5.7
MEDIUMCVE-2021-31222
SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.... Read more
Affected Products : endpoint_security- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-22784
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.... Read more
Affected Products : c-bus_toolkit- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2020-19268
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.... Read more
Affected Products : dswjcms- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-36285
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a bru... Read more
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-35203
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.... Read more
Affected Products : ngeniusone- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-35601
Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Students Administration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with... Read more
Affected Products : peoplesoft_enterprise_cs_sa_integration_pack- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-25501
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.... Read more
- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-8790
Huawei CloudEngine 5800 with software before V200R001C00SPC700, CloudEngine 6800 with software before V200R001C00SPC700, CloudEngine 7800 with software before V200R001C00SPC700, CloudEngine 8800 with software before V200R001C00SPC700, CloudEngine 12800 wi... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2018-5448
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.... Read more
- Published: May. 04, 2018
- Modified: May. 22, 2025
-
5.7
MEDIUMCVE-2023-7031
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 ... Read more
Affected Products : aura_experience_portal- Published: Jan. 17, 2024
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-0169
Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to I... Read more
Affected Products : unity_operating_environment- Published: Feb. 12, 2024
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-4694
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.... Read more
Affected Products : memos- Published: Dec. 27, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-23933
OpenSearch Anomaly Detection identifies atypical data and receives automatic notifications. There is an issue with the application of document and field level restrictions in the Anomaly Detection plugin, where users with the Anomaly Detector role can rea... Read more
Affected Products : opensearch- Published: Feb. 03, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-47364
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025
-
5.7
MEDIUMCVE-2022-47369
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025
-
5.7
MEDIUMCVE-2022-47363
In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025
-
5.7
MEDIUMCVE-2018-11293
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, in wma_ndp_confirm_event_handler and wma_ndp_indication_event_handler, ndp_cfg len and num_ndp_app_info is from fw. If they are not checked, it may... Read more
Affected Products : android- Published: Sep. 18, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2017-14956
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send ... Read more
Affected Products : unified_security_management- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2023-2630
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.... Read more
Affected Products : pimcore- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-3228
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.... Read more
Affected Products : fossbilling- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024