Latest CVE Feed
-
4.3
MEDIUMCVE-2021-30477
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not ... Read more
Affected Products : zulip_server- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30478
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, incl... Read more
Affected Products : zulip_server- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4864
IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567.... Read more
Affected Products : resilient_security_orchestration_automation_and_response- Published: Oct. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6070
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where... Read more
Affected Products : enterprise_security_manager- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32447
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. ... Read more
Affected Products : awp_classifieds- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6625
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2024-3664
The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible fo... Read more
Affected Products :- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6493
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' func... Read more
Affected Products : depicter_slider- Published: Jan. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4548
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Conte... Read more
- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4846
Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.... Read more
Affected Products : metaslider- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-46599
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-5315
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by s... Read more
Affected Products : gitlab- Published: Jun. 26, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-32962
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 ... Read more
- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2023-48296
OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. This vulnerabilit... Read more
- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-22316
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.... Read more
Affected Products : sterling_file_gateway- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2022-0985
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.... Read more
Affected Products : moodle- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-54384
Missing Authorization vulnerability in eLightUp Falcon – WordPress Optimizations & Tweaks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through 2.8.3.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
4.3
MEDIUMCVE-2025-32728
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.... Read more
- Published: Apr. 10, 2025
- Modified: May. 22, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-5682
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.7.... Read more
Affected Products : klaro_cookie_\&_consent_management- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-5730
The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting