Latest CVE Feed
-
4.3
MEDIUMCVE-2017-15014
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an au... Read more
Affected Products : documentum_content_server- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-52380
Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Feb. 18, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2023-50951
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.... Read more
- Published: Feb. 17, 2024
- Modified: Dec. 03, 2024
-
4.3
MEDIUM- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2018-2598
Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security: Encryption). Supported versions that are affected are 6.3.10 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network ac... Read more
Affected Products : mysql_workbench- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42663
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the we... Read more
Affected Products : online_event_booking_and_reservation_system- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48063
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.... Read more
- Published: Nov. 13, 2023
- Modified: Apr. 04, 2025
-
4.3
MEDIUMCVE-2023-24463
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products : thunderbolt_dch_driver- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-25971
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file... Read more
Affected Products : camaleon_cms- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-25643
The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access informat... Read more
Affected Products : fiori- Published: Feb. 13, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-15199
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15198
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15203
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15206
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15211
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-6741
The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.... Read more
Affected Products : wp_customer_area- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2023-6292
The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.... Read more
Affected Products : ecwid_ecommerce_shopping_cart- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2023-3178
The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2022-1760
The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : core_control- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2023-49099
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.... Read more
Affected Products : discourse- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024