Latest CVE Feed
-
4.3
MEDIUMCVE-2013-5863
Unspecified vulnerability in Oracle Solaris 11.1 allows remote attackers to affect integrity via vectors related to IPS repository daemon.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-16704
An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possible for attackers (logged in users) to view profile page of other users, as demonstrated by navigating to user/3 on demo.gleezcms.org.... Read more
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1843
The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image... Read more
Affected Products : docker- Published: Apr. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-19582
GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.... Read more
Affected Products : gitlab- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0746
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.... Read more
Affected Products : dolibarr_erp\/crm- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3413
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.... Read more
Affected Products : kde_pim- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName ... Read more
- Published: Jul. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-3127
Vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite (subcomponent: Product Security). Supported versions that are affected are 7.3.5 and 12.2. Easily exploitable vulnerability allows unauthenticated attac... Read more
Affected Products : demantra_demand_management- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5911
Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : securitycenter- Published: Sep. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6344
The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.... Read more
Affected Products : zenworks_configuration_management- Published: Nov. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1586
Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.... Read more
Affected Products : system_management_homepage- Published: Apr. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6397
Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XS... Read more
Affected Products : solr- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1644
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) descript... Read more
Affected Products : cacti- Published: Aug. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2153
The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference eleme... Read more
Affected Products : xml_security_for_c\+\+- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3219
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for D... Read more
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-17450
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP serv... Read more
Affected Products : gitlab- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025
-
4.3
MEDIUMCVE-2015-2017
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting atta... Read more
Affected Products : websphere_application_server- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1515
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Middleware Products 3.0.1 and 3.1.2 allows remote attackers to affect integrity via vectors related to ADMIN Interface.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3130
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.... Read more
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-9633
The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.83. This is due to missing or incorrect nonce validation on the plugin_options function. This makes it possible for unauthenticated att... Read more
Affected Products :- Published: Sep. 11, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Cross-Site Request Forgery