Latest CVE Feed
-
5.7
MEDIUMCVE-2024-50995
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-51000
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a ... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2020-13344
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis... Read more
Affected Products : gitlab- Published: Oct. 08, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2019-11251
The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified i... Read more
Affected Products : kubernetes- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-4859
Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL. ... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-29432
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.... Read more
Affected Products : sydent- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-2116
Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2021-25011
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's se... Read more
Affected Products : wp_google_map- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-24968
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Sub... Read more
Affected Products : ultimate_faq- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-24752
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPre... Read more
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-24703
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.... Read more
Affected Products : download_plugin- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-50157
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2018-1000161
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a vict... Read more
Affected Products : nmap- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-1001
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modi... Read more
Affected Products :- Published: Feb. 21, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2018-0414
A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entitie... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2017-9546
admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revision name.... Read more
Affected Products : bigtree_cms- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-8969
An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.... Read more
Affected Products : insight_control- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-3563
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer deref... Read more
- Published: Oct. 17, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-22711
Windows BitLocker Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_server_2022 windows_11_21h2 +5 more products- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-3426
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user t... Read more
- Published: May. 20, 2021
- Modified: Nov. 21, 2024