Latest CVE Feed
-
4.3
MEDIUMCVE-2020-11810
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been ... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-14183
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected ve... Read more
- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43105
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2017-10133
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RestAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access v... Read more
Affected Products : hospitality_hotel_mobile- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8302
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnera... Read more
Affected Products : flexcube_universal_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2022-27199
A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.... Read more
Affected Products : cloudbees_aws_credentials- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-10071
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: All Modules). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily expl... Read more
Affected Products : flexcube_universal_banking- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1002024
Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.... Read more
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-10889
TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.... Read more
Affected Products : tablepress- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2020-27759
In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some cases caused a value outside the range of type `int` to be returned. The flaw could be triggered by a crafted input file under certain cond... Read more
- Published: Dec. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2772
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Absence Recording, Maintenance). Supported versions that are affected are 12.2.6-12.2.9. Easily exploitable vulnerability allows low privileged attacker with networ... Read more
Affected Products : human_resources- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-15337
The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP630... Read more
Affected Products : nip6800_firmware secospace_usg6600_firmware usg9500_firmware vp9660_firmware espace_u1981_firmware dp300_firmware te60_firmware viewpoint_9030_firmware secospace_usg6300_firmware rp200_firmware +42 more products- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-32205
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.... Read more
- Published: Jun. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-13873
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive netw... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21228
Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.... Read more
- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21639
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with ... Read more
Affected Products : jenkins- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-12625
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement d... Read more
Affected Products : hive- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2024-43927
Cross-Site Request Forgery (CSRF) vulnerability in Till Krüss Email Address Encoder allows Cross Site Request Forgery.This issue affects Email Address Encoder: from n/a through 1.0.23.... Read more
Affected Products : email_address_encoder- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2017-0888
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of informat... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-13877
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to determine whether arbitrary files exist via a crafted app.... Read more
Affected Products : iphone_os- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024