Latest CVE Feed
-
4.3
MEDIUMCVE-2016-2928
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-22708
Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7.... Read more
Affected Products : kraken.io_image_optimizer- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2019-6790
An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests... Read more
Affected Products : gitlab- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-29046
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the co... Read more
Affected Products : open-xchange_appsuite- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-16862
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.... Read more
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-3182
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnera... Read more
Affected Products : webex_meetings- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-29064
The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets used by the application, which include tokens and passwords for administrative accounts.... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1341
IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access. IBM X-Force ID: 126456.... Read more
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2004-1849
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.... Read more
Affected Products : cpanel- Published: Mar. 24, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-3222
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device. The vulnerability is due to the presence of a proxy service at... Read more
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-28334
Authenticated users were able to enumerate other users' names via the learning plans page.... Read more
Affected Products : moodle- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-29065
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database.... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1412
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.... Read more
Affected Products : esupport- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-8727
A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting a malicious website may lead to address bar spoofing.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-2632
Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attac... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1527
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.... Read more
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1657
Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.... Read more
Affected Products : dasblog- Published: Sep. 01, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1735
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : sympa- Published: Aug. 21, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-1413
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.... Read more
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1534
Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.... Read more
Affected Products : guestbook- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025