Latest CVE Feed
-
5.4
MEDIUMCVE-2014-6650
The NextGenUpdate (aka com.tapatalk.nextgenupdatecomforums) application 3.1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : nextgenupdate- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6643
The FIAT Forum (aka com.tapatalk.fiatforumcom) application 3.8.41 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : fiat_forum- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6667
The racemotocross (aka com.bossappsmk.racemotocross) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : racemotocross- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6655
The Tortoise Forum (aka org.tortoiseforum.android.forumrunner) application 3.5.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer... Read more
Affected Products : tortoise_forum- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6640
The DNB Trade (aka lt.dnb.mobiletrade) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dnb_trade- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6647
The ElForro.com (aka com.tapatalk.elforrocom) application 2.4.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : elforro.com- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6648
The iPhone4.TW (aka com.tapatalk.iPhone4TWforums) application 3.3.20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : iphone4.tw- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6636
The LG Telepresence (aka com.rsupport.rtc.lge) application 2.0.12 Build 63 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : lg_telepresence- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-43808
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin... Read more
Affected Products : teamcity- Published: Aug. 16, 2024
- Modified: Aug. 19, 2024
-
5.4
MEDIUMCVE-2014-6661
The netease movie (aka com.netease.movie) application 4.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : netease_movie- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6658
The Apploi Job Search- Find Jobs (aka com.apploi) application 4.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : apploi_job_search-_find_jobs- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6680
The superheroquiz (aka com.davidhey.superheroquiz) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : superheroquiz- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6646
The bellyhoodcom (aka com.tapatalk.bellyhoodcom) application 3.4.23 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : bellyhoodcom- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-20251
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This v... Read more
Affected Products : identity_services_engine- Published: Jan. 17, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6675
The Ruta Exacta (aka com.rutaexacta.m) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ruta_exacta- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6671
The World Cup 2014 Brazil - Xem TV (aka vn.letshare.football.worldcup) application 2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte... Read more
Affected Products : world_cup_2014_brazil_-_xem_tv- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-49025
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability... Read more
Affected Products : edge_chromium- Published: Nov. 14, 2024
- Modified: Jan. 07, 2025
-
5.4
MEDIUMCVE-2014-6191
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.... Read more
Affected Products : curam_social_program_management- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-2731
Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive information such as company names, users' names and surnames, stage names, and monitoring campaigns and their des... Read more
Affected Products : mautic- Published: Apr. 10, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6169
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.... Read more
Affected Products : forms_experience_builder- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024