Latest CVE Feed
-
4.3
MEDIUMCVE-2015-3234
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.... Read more
- Published: Jun. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1637
Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS s... Read more
- Published: Mar. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-20620
Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : ssh_agent- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-25615
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows cache deletion.... Read more
Affected Products : eroom_-_zoom_meetings_\&_webinar- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4414
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it pos... Read more
Affected Products : abandoned_cart_lite_for_woocommerce- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21691
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions chat participants can spoof their channel leave message, tricking others into assuming t... Read more
Affected Products : onionshare- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-25266
Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).... Read more
Affected Products : passwork- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1203
The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as su... Read more
Affected Products : content_mask- Published: May. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4089
snipe-it is vulnerable to Improper Access Control... Read more
Affected Products : snipe-it- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-44436
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT... Read more
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21532
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with netw... Read more
Affected Products : jd_edwards_enterpriseone_orchestrator- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21713
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data ... Read more
- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-24890
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is avail... Read more
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1100
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which caused exponenti... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21642
Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2.8.0.... Read more
Affected Products : discourse- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1459
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.... Read more
Affected Products : bitdefender nod32_antivirus v3_internet_security clamav antivirus norman_antivirus_\&_antispyware panda_antivirus rising_antivirus virusbuster f-prot_antivirus +24 more products- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-4122
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanentl... Read more
Affected Products : cryptsetup- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20618
A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : bitbucket_branch_source- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21589
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.39 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with netwo... Read more
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20614
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.... Read more
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024