Latest CVE Feed
-
4.3
MEDIUMCVE-2023-5385
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_copy_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with ... Read more
- Published: Nov. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-49240
Missing Authorization vulnerability in nK DocsPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DocsPress: from n/a through 2.5.2.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2011-4920
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26, and other versions before 1.0.0, allow remote attackers to inject arbitrary web script or HTML via the URL to (1) e107_images/thumb.php or (2) rate.php, (3) resend_name parameter to e107_... Read more
Affected Products : e107- Published: Jan. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-28913
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Ali Muni WP Add Active Class To Menu Item allows Cross Site Request Forgery. This issue affects WP Add Active Class To Menu Item: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2009-1620
Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters.... Read more
Affected Products : matachat- Published: May. 12, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1220
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode ... Read more
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-45164
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - even if this basic user is not a member of the booking... Read more
- Published: Jan. 10, 2023
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2006-6824
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) w... Read more
Affected Products : php_icalendar- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-33264
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.... Read more
Affected Products : hazelcast- Published: May. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-42339
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products : identity- Published: Aug. 25, 2024
- Modified: Aug. 30, 2024
-
4.3
MEDIUMCVE-2022-23688
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the ... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2049
The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message.... Read more
Affected Products : mail_server- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1616
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505.... Read more
- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-42222
In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised acces... Read more
Affected Products : cloudstack- Published: Aug. 07, 2024
- Modified: Mar. 14, 2025
-
4.3
MEDIUMCVE-2024-55994
Missing Authorization vulnerability in 搜狐畅言 畅言评论系统 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 畅言评论系统: from n/a through 2.0.5.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
4.3
MEDIUMCVE-2011-5159
Cross-site scripting (XSS) vulnerability in admin/configuration.php in Geeklog before 1.7.1sr1 allows remote attackers to inject arbitrary web script or HTML via the sub_group parameter, a different vulnerability than CVE-2011-4942.... Read more
Affected Products : geeklog- Published: Sep. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-11334
An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay. Physically... Read more
- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1342
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for ... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-31293
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing ... Read more
Affected Products : cash_point_\&_transport_optimizer- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50951
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.... Read more
- Published: Feb. 17, 2024
- Modified: Dec. 03, 2024