Latest CVE Feed
-
5.7
MEDIUMCVE-2025-2102
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2024-46327
An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.... Read more
- Published: Sep. 26, 2024
- Modified: Jun. 24, 2025
-
5.7
MEDIUMCVE-2023-38491
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors ... Read more
Affected Products : kirby- Published: Jul. 27, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-52509
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and t... Read more
- Published: Nov. 15, 2024
- Modified: Sep. 04, 2025
-
5.7
MEDIUMCVE-2024-52361
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access to the pod.... Read more
Affected Products : storage_defender_resiliency_service- Published: Dec. 18, 2024
- Modified: Aug. 08, 2025
-
5.7
MEDIUMCVE-2022-34572
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.... Read more
Affected Products : wifi-repeater_firmware- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-50121
Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).... Read more
- Published: Jan. 06, 2024
- Modified: Apr. 17, 2025
-
5.7
MEDIUMCVE-2020-14292
In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public... Read more
Affected Products : covidsafe- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2018-2389
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.... Read more
Affected Products : internet_graphics_server- Published: Feb. 14, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.... Read more
Affected Products : carbon- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2005-4825
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP s... Read more
Affected Products : network_admission_control_manager_and_server_system_software- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.7
MEDIUMCVE-2019-14680
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.... Read more
Affected Products : admin-renamer-extended- Published: Aug. 08, 2019
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2019-3419
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.... Read more
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2020-24721
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disprov... Read more
- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2019-5211
The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management vulnerability. The attacker tricks the victim to perform certain operations on the mobile phone during file transfer. Because the file ... Read more
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-32793
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-... Read more
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-0245
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-25569
Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any... Read more
Affected Products : apollo- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-6146
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS... Read more
Affected Products : private_cloud_platform- Published: Dec. 08, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-29680
Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.... Read more
- Published: May. 01, 2023
- Modified: Jan. 30, 2025