Latest CVE Feed
-
4.3
MEDIUMCVE-2019-4442
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID:... Read more
Affected Products : websphere_application_server- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2909
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker wit... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-20275
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address... Read more
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4184
Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-6096
Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login p... Read more
- Published: Feb. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-0691
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to ... Read more
Affected Products : metform_elementor_contact_form_builder- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-41708
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.... Read more
Affected Products : messenger- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2024-58265
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.... Read more
Affected Products : snow- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2014-0866
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-56348
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents... Read more
Affected Products : teamcity- Published: Dec. 20, 2024
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2013-1955
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php and (2) datePicker.php in Easy PHP Calendar 6.x and 7.x before 7.0.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : easy_php_calendar- Published: Jul. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-5438
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. T... Read more
Affected Products : tutor_lms- Published: Jun. 07, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4565
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm p... Read more
Affected Products : verification_code_for_comments- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4074
The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of outp... Read more
Affected Products : internet_explorer- Published: Nov. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-0453
The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private... Read more
Affected Products : wp_private_messaging- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
4.3
MEDIUMCVE-2022-41263
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise re... Read more
Affected Products : business_objects_business_intelligence_platform- Published: Dec. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3903
Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp in ManageEngine Netflow Analyzer 7.5 build 7500 allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) section parameters. NOTE: the provenance of this... Read more
- Published: Nov. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2002-2260
Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.... Read more
Affected Products : bugzilla- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-56350
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects... Read more
Affected Products : teamcity- Published: Dec. 20, 2024
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2023-1924
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024