Latest CVE Feed
-
4.3
MEDIUMCVE-2024-6579
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it po... Read more
Affected Products :- Published: Jul. 16, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3071
The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the acfg_update_fields() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attacker... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-27525
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 ... Read more
Affected Products : superset- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4942
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated ... Read more
Affected Products : bear_-_woocommerce_bulk_editor_and_products_manager_professional- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6598
The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_d... Read more
Affected Products : speedycache- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6742
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.... Read more
Affected Products : envira_gallery- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34803
Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5930
Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'.... Read more
Affected Products : garoon- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-13439
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 4.4.9. This makes it possible for authenticated attackers,... Read more
Affected Products : team- Published: Feb. 15, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2014-0337
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted ... Read more
- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-29962
Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.... Read more
Affected Products : firefox- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0899
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of ... Read more
- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-3843
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).... Read more
Affected Products : prime_collaboration_assurance- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-0660
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.... Read more
Affected Products : mahara- Published: Mar. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-47585
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import... Read more
Affected Products : netweaver_application_server_abap- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2017-3322
Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: NDBAPI). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier and . Difficult to exploit vulnerability allows unauthenticat... Read more
Affected Products : mysql_cluster- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-0312
Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.... Read more
- Published: Jan. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-3871
A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The ... Read more
Affected Products : prime_optical- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-18467
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0146
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JB... Read more
- Published: Apr. 23, 2009
- Modified: Apr. 09, 2025