Latest CVE Feed
-
4.3
MEDIUMCVE-2012-6316
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to us... Read more
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-53268
Cross-Site Request Forgery (CSRF) vulnerability in ryanpcmcquen Import external attachments allows Cross Site Request Forgery. This issue affects Import external attachments: from n/a through 1.5.12.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2017-8164
Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160... Read more
Affected Products : vie-l09_firmware eva-al10_firmware eva-cl00_firmware eva-dl00_firmware eva-l09_firmware eva-l19_firmware eva-l29_firmware eva-tl00_firmware vie-l29_firmware eva-l09 +8 more products- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4931
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible ... Read more
Affected Products : backupwordpress- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-23265
A logged-in and authenticated user with a Reviewer Role may lock a content item.... Read more
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-48079
Missing Authorization vulnerability in Metagauss ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ProfileGrid : from n/a through 5.9.5.1.... Read more
Affected Products : profilegrid- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2016-1474
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)... Read more
Affected Products : prime_infrastructure- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-10208
Vulnerability in the Oracle Hospitality e7 component of Oracle Hospitality Applications (subcomponent: Other). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via SMTP to... Read more
Affected Products : hospitality_e7- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-36994
There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist.... Read more
- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37190
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.... Read more
Affected Products : sinema_remote_connect_server- Published: Sep. 14, 2021
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2021-37193
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as inva... Read more
Affected Products : sinema_remote_connect_server- Published: Sep. 14, 2021
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2016-8308
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows... Read more
Affected Products : flexcube_private_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8301
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnera... Read more
Affected Products : flexcube_universal_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-34765
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-b... Read more
Affected Products : nexus_insights- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0378
IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.... Read more
Affected Products : websphere_application_server- Published: Nov. 24, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-7965
The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2017-6783
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the applia... Read more
Affected Products : web_security_appliance email_security_appliance content_security_management_appliance- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-46388
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-21014
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2021-41250
Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted URL and an otherwise triggering filter token is included in the same message the token filter does not trigger. This means that by includ... Read more
Affected Products : bot- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024