Latest CVE Feed
-
4.3
MEDIUMCVE-2020-36660
A vulnerability was found in paxswill EVE Ship Replacement Program 0.12.11. It has been rated as problematic. This issue affects some unknown processing of the file src/evesrp/views/api.py of the component User Information Handler. The manipulation leads ... Read more
Affected Products : eve_ship_replacement_program- Published: Feb. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0829
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible f... Read more
- Published: Mar. 13, 2024
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2018-16971
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.... Read more
Affected Products : learning_management_system- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1777
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the settings update function. This makes i... Read more
Affected Products : admin_side_data_storage_for_contact_form_7- Published: Feb. 23, 2024
- Modified: Jan. 16, 2025
-
4.3
MEDIUMCVE-2018-2598
Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security: Encryption). Supported versions that are affected are 6.3.10 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network ac... Read more
Affected Products : mysql_workbench- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50951
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.... Read more
- Published: Feb. 17, 2024
- Modified: Dec. 03, 2024
-
4.3
MEDIUMCVE-2016-7823
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-52380
Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Feb. 18, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2018-1587
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an adversary to gain information about t... Read more
- Published: Jul. 19, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1652
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated at... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2018-1773
IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed. IBM X-Force ID: 148691.... Read more
Affected Products : datacap- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2473
Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product.... Read more
Affected Products : openwiki- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-23616
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the re... Read more
Affected Products : discourse- Published: Jan. 28, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48063
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.... Read more
- Published: Nov. 13, 2023
- Modified: Apr. 04, 2025
-
4.3
MEDIUMCVE-2021-22303
There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause pointer double free.... Read more
- Published: Feb. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4520
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.... Read more
- Published: Dec. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-6980
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the... Read more
Affected Products : wp_sms- Published: Jan. 03, 2024
- Modified: Jul. 11, 2025
-
4.3
MEDIUMCVE-2018-11346
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.... Read more
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48393
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.... Read more
Affected Products : webitr_attendance_system- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2116
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.... Read more
Affected Products : office- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025