Latest CVE Feed
-
4.3
MEDIUMCVE-2024-49419
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.... Read more
Affected Products :- Published: Dec. 03, 2024
- Modified: Dec. 03, 2024
-
4.3
MEDIUMCVE-2024-10667
The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1.5 via the [csb] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticat... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2024-10688
The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 via the 'attesa-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authent... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2017-1768
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471.... Read more
Affected Products : security_guardium_big_data_intelligence- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6348
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6361
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE files received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is ca... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6307
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.... Read more
Affected Products : basis- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29433
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource e... Read more
Affected Products : sydent- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32525
Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4512
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.... Read more
- Published: Oct. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5228
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details ar... Read more
Affected Products : phplist- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6541
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action ... Read more
Affected Products : neuron_news- Published: Dec. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4507
Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2700
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : clickbank_affiliate_marketplace_script- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-7182
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker... Read more
Affected Products : wp_go_maps- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-3936
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and includ... Read more
Affected Products : the_post_grid- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2723
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party infor... Read more
Affected Products : listserv- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-41657
Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.... Read more
Affected Products :- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2013-4594
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.... Read more
Affected Products : payment_for_webform- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-45164
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - even if this basic user is not a member of the booking... Read more
- Published: Jan. 10, 2023
- Modified: May. 30, 2025