Latest CVE Feed
-
4.3
MEDIUMCVE-2021-31608
Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.... Read more
Affected Products : enterprise_protection- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2006-2228
Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals) char... Read more
Affected Products : w-agora- Published: May. 05, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-7469
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.... Read more
Affected Products : jazz_reporting_service- Published: Jan. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1474
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)... Read more
Affected Products : prime_infrastructure- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-2267
The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to ... Read more
Affected Products : mailchimp_for_woocommerce- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-49972
Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy allows Cross Site Request Forgery. This issue affects TM Replace Howdy: from n/a through 1.4.2.... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2015-7784
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
- Published: Dec. 30, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-25954
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is a... Read more
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-6859
Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggering an error and then reading a Java stack trace.... Read more
Affected Products : hybris- Published: Dec. 31, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-36473
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.... Read more
- Published: Aug. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-39284
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed ... Read more
Affected Products : codeigniter- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3511
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a s... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-47298
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account status... Read more
Affected Products : terminal_handler- Published: Jun. 23, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2016-1862
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.... Read more
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-54035
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters allows Cross Site Request Forgery. This issue affects Newsletters: from n/a through 4.10.... Read more
Affected Products : newsletters- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2022-27219
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more pron... Read more
Affected Products : sinema_remote_connect_server- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-45103
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.... Read more
- Published: Sep. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2017-1326
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-2304
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.... Read more
Affected Products : integraxor- Published: Apr. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-32169
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.... Read more
Affected Products : bytebase- Published: Sep. 28, 2022
- Modified: May. 21, 2025