Latest CVE Feed
-
4.3
MEDIUMCVE-2023-5973
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and chang... Read more
- Published: Apr. 05, 2024
- Modified: Feb. 13, 2025
-
4.3
MEDIUMCVE-2024-48290
An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2021-30144
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.p... Read more
- Published: Apr. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-46288
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configu... Read more
Affected Products : airflow- Published: Oct. 23, 2023
- Modified: Feb. 13, 2025
-
4.3
MEDIUMCVE-2022-27575
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22896
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.... Read more
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31393
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.... Read more
- Published: Apr. 03, 2024
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-22769
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.... Read more
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32787
Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.7.1.... Read more
Affected Products :- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-2435
For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when a victim views that signal. The XSS is in the timeline page displaying the workflow execution details of the workflo... Read more
Affected Products :- Published: Apr. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12636
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation... Read more
Affected Products :- Published: Dec. 25, 2024
- Modified: Dec. 25, 2024
-
4.3
MEDIUMCVE-2017-13269
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68818034.... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30493
Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.7. ... Read more
Affected Products : church_admin- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6491
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authe... Read more
- Published: Jul. 20, 2024
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2024-36122
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the... Read more
Affected Products : discourse- Published: Jul. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33605
Improper check in CheckboxGroup in com.vaadin:vaadin-checkbox-flow versions 1.2.0 prior to 2.0.0 (Vaadin 12.0.0 prior to 14.0.0), 2.0.0 prior to 3.0.0 (Vaadin 14.0.0 prior to 14.5.0), 3.0.0 through 4.0.1 (Vaadin 15.0.0 through 17.0.11), 14.5.0 through 14.... Read more
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-5804
The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it pos... Read more
Affected Products :- Published: Jul. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-32707
Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attri... Read more
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-2970
The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the nwap_newslist_page() function. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-2476
The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subs... Read more
Affected Products :- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024