Latest CVE Feed
-
4.3
MEDIUMCVE-2008-1716
Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when... Read more
Affected Products : burning_board- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1047
Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vecto... Read more
- Published: Mar. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-7380
The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to, and including, 8.6.9. This makes it ... Read more
Affected Products : geo_controller- Published: Sep. 05, 2024
- Modified: Sep. 06, 2024
-
4.3
MEDIUMCVE-2024-1092
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and incl... Read more
Affected Products : rss_aggregator_by_feedzy- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4571
Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter.... Read more
Affected Products : vn-calendar- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1103
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the me... Read more
- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-2846
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticate... Read more
Affected Products : calendar_event_multi_view- Published: Aug. 16, 2022
- Modified: Apr. 15, 2025
-
4.3
MEDIUMCVE-2016-8217
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed ... Read more
Affected Products : bsafe_crypto-j- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-2392
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-s... Read more
Affected Products : open-xchange_appsuite- Published: Apr. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-23575
Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass access restriction and access Network Maintenance page, which may result in obtaining the network information of the product. The affe... Read more
Affected Products : cps-mg341-adsc1-111_firmware cps-mg341-adsc1-931_firmware cps-mg341g-adsc1-111_firmware cps-mg341g-adsc1-930_firmware cps-mg341g5-adsc1-931_firmware cps-mc341-adsc1-111_firmware cps-mc341-adsc1-931_firmware cps-mc341-adsc2-111_firmware cps-mc341g-adsc1-110_firmware cps-mc341q-adsc1-111_firmware +28 more products- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2024-43215
Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.... Read more
Affected Products : social_slider_widget- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2012-3833
Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.... Read more
Affected Products : quick.cms- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3836
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) groupname parameter in a savecategory in the users module; (2) virtual_filename, (3) branch, (4) conta... Read more
Affected Products : baby_gekko- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-29270
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.... Read more
Affected Products : nagios_xi- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-29417
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.... Read more
Affected Products : shortpixel_adaptive_images- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1091
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible for authen... Read more
Affected Products : imagerecycle_pdf_\&_image_compression- Published: Feb. 29, 2024
- Modified: Dec. 27, 2024
-
4.3
MEDIUMCVE-2024-22339
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from so... Read more
- Published: Apr. 12, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2024-5808
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack... Read more
Affected Products : wp_ajax_contact_form- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2021-42122
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric format allows an authenticated remote attacker with Object Modification privileges to i... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30216
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affect... Read more
Affected Products :- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024