Latest CVE Feed
-
4.3
MEDIUMCVE-2021-33330
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers t... Read more
- Published: Aug. 03, 2021
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2021-34886
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-38221
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Sep. 19, 2024
- Modified: Sep. 23, 2024
-
4.3
MEDIUMCVE-2022-0334
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradere... Read more
Affected Products : moodle- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34890
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-23996
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.... Read more
Affected Products : wear_os- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4541
The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation when modifying products. This makes it possible for unauthenti... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34901
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34916
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4873
The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for au... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34943
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-1410
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authori... Read more
Affected Products : webex_meetings- Published: Nov. 18, 2024
- Modified: Aug. 05, 2025
-
4.3
MEDIUMCVE-2024-47337
Missing Authorization vulnerability in Stuart Wilson Joy Of Text Lite.This issue affects Joy Of Text Lite: from n/a through 2.3.1.... Read more
Affected Products : joy_of_text_lite- Published: Sep. 26, 2024
- Modified: Sep. 26, 2024
-
4.3
MEDIUMCVE-2021-32991
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.... Read more
Affected Products : diaenergie- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8552
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, w... Read more
Affected Products : download_monitor- Published: Sep. 26, 2024
- Modified: Oct. 02, 2024
-
4.3
MEDIUMCVE-2022-24782
Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior in the `beta` branch, and 2.9.0.beta3 and prior in the `tests-passed` branch are vulnerable to a data leak. Users can request an export... Read more
Affected Products : discourse- Published: Mar. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42062
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor... Read more
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-31506
This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
Affected Products : brava\!_desktop- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3945
The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to missing or incorrect nonce validation on the wptodo_manage() function. This makes it possible for unauthenticated att... Read more
Affected Products : wp_to_do- Published: May. 30, 2024
- Modified: Feb. 12, 2025
-
4.3
MEDIUMCVE-2024-10437
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capability check on the ajax_enable function in all versions up to, and including, 4.2.1. This makes it possibl... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024