Latest CVE Feed
-
4.3
MEDIUMCVE-2019-16116
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.... Read more
Affected Products : completeftp_server- Published: Oct. 02, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-1480
An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481.... Read more
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6772
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking... Read more
Affected Products : splunk- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5481
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/e... Read more
Affected Products : gd_bbpress_attachments- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-4601
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.... Read more
Affected Products : rational_quality_manager- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-0390
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.... Read more
Affected Products : diagnostics_agent- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-18399
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1899
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.... Read more
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6255
Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-Mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via a crafted chat message, aka Bug ID CSCuo89051.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6929
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilte... Read more
Affected Products : \@vantage_commander- Published: Sep. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-0278
Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database tables used by the application, lead... Read more
Affected Products : netweaver_process_integration- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-16768
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some interna... Read more
Affected Products : sylius- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9784
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.... Read more
Affected Products : safari- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9468
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.... Read more
Affected Products : piwigo- Published: Mar. 26, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-10835
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2700
Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network ac... Read more
- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6663
Cross-site scripting (XSS) vulnerability in the Client form in the Device Inspector page in SAP Afaria 7 allows remote attackers to inject arbitrary web script or HTML via crafted client name data, aka SAP Security Note 2152669.... Read more
Affected Products : afaria- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-18445
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-18440
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5465
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.... Read more
Affected Products : gitlab- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024