Latest CVE Feed
-
4.3
MEDIUMCVE-2002-1453
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.... Read more
Affected Products : mywebserver- Published: Aug. 14, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-47327
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.... Read more
Affected Products : silverpeas- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-9978
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.... Read more
Affected Products : curam_social_program_management- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-3201
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged requ... Read more
Affected Products : mstore_api- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-44284
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL comm... Read more
- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6980
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the... Read more
Affected Products : wp_sms- Published: Jan. 03, 2024
- Modified: Jul. 11, 2025
-
4.3
MEDIUMCVE-2021-4082
pimcore is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : pimcore- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2819
A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (PTR/TRAP) could allow an authenticated administrator on an adjacent network to replace the image file with an arbitrary MIME type. Thi... Read more
Affected Products : threat_response_auto_pull- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-0881
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from... Read more
Affected Products : zulip_server- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-38509
XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-milestone-1 and prior to versions 14.10.9 and 15.3-rc-1, the mail obfuscation configuration was not fully taken into account and is was ... Read more
Affected Products : xwiki- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4627
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-l... Read more
Affected Products : ladipage- Published: Mar. 12, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2018-0528
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.... Read more
Affected Products : office- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-9461
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated att... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-31293
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing ... Read more
Affected Products : cash_point_\&_transport_optimizer- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4189
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system. IBM X-Force ID: 174850.... Read more
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4729
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to... Read more
Affected Products : ladipage- Published: Mar. 12, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2022-4125
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stor... Read more
Affected Products : popup_manager- Published: Dec. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-42768
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2021-41250
Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted URL and an otherwise triggering filter token is included in the same message the token filter does not trigger. This means that by includ... Read more
Affected Products : bot- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50951
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.... Read more
- Published: Feb. 17, 2024
- Modified: Dec. 03, 2024