Latest CVE Feed
-
4.3
MEDIUMCVE-2023-50923
In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which might allow remote attackers to construct a covert channel with data represented as changes to the bit val... Read more
Affected Products :- Published: Feb. 21, 2024
- Modified: Dec. 04, 2024
-
4.3
MEDIUMCVE-2015-3189
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a n... Read more
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2022-1895
The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack... Read more
Affected Products : underconstruction- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-15871
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.... Read more
Affected Products : loginpress- Published: Sep. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0809
Unspecified vulnerability in the Web ADI component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3596
Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7 allows remote attackers to inject arbitrary web script or HTML via the Username field, which is inserted into logs that could be rendered when viewed by an administrator.... Read more
Affected Products : harmoni- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-27907
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.... Read more
Affected Products : nexus_repository_manager- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3710
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product instal... Read more
Affected Products : suse_lifecycle_management_server- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-23686
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the ... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4433
Cross-site scripting (XSS) vulnerability in textfilesearch.aspx in the Text File Search ASP.NET edition allows remote attackers to inject arbitrary web script or HTML via the search field.... Read more
Affected Products : text_file_search- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3342
Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.... Read more
Affected Products : easypublish- Published: Jul. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-1594
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL... Read more
Affected Products : hc_custom_wp-admin_url- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2733
Vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite (subcomponent: Product Security). The supported version that is affected is 7.3.1.5.2. Easily exploitable vulnerability allows low privileged attacker w... Read more
Affected Products : demantra_demand_management- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0911
inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.... Read more
Affected Products : websphere_mq- Published: May. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-1983
Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1205
Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when... Read more
Affected Products : mybloggie- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-1317
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.... Read more
- Published: Feb. 09, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1908
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : splunk- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-1501
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.... Read more
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-5066
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine randomly ... Read more
Affected Products : virtual_war- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025