Latest CVE Feed
-
4.3
MEDIUMCVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visi... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2021-37190
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.... Read more
Affected Products : sinema_remote_connect_server- Published: Sep. 14, 2021
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2021-36542
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's w... Read more
Affected Products : seeddms- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33327
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the G... Read more
- Published: Aug. 03, 2021
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2024-45193
An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects produc... Read more
Affected Products : olm- Published: Aug. 22, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2025-39398
Missing Authorization vulnerability in Themovation Hotel + Bed and Breakfast Booking Calendar Theme | Bellevue.This issue affects Hotel + Bed and Breakfast Booking Calendar Theme | Bellevue: from n/a through 4.2.2.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-4683
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes i... Read more
Affected Products : mstore_api- Published: May. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2016-7823
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2022-1845
The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attackers to make a logged in admin delete plugin's data, update the settings, add new entries and more via CSRF attacks... Read more
Affected Products : wp_post_styling- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-32002
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on ... Read more
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43955
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-7581
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Safari" component, which allows remote web servers to cause a denial of service via a crafted URL.... Read more
Affected Products : iphone_os- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-8401
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-... Read more
Affected Products : ht_mega- Published: Jul. 31, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2017-5866
The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : owncloud- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-25971
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file... Read more
Affected Products : camaleon_cms- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-43835
Cross-Site Request Forgery (CSRF) vulnerability in ktsvetkov allows Cross Site Request Forgery.This issue affects wp-cyr-cho: from n/a through 0.1.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2017-1099
IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.... Read more
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2022-25223
Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter.... Read more
Affected Products : money_transfer_management_system- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-39897
zot is an OCI image registry. Prior to 2.1.0, the cache driver `GetBlob()` allows read access to any blob without access control check. If a Zot `accessControl` policy allows users read access to some repositories but restricts read access to other reposi... Read more
Affected Products : zot- Published: Jul. 09, 2024
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2025-39375
Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery