Latest CVE Feed
-
4.3
MEDIUMCVE-2023-6959
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authen... Read more
- Published: Feb. 05, 2024
- Modified: Nov. 25, 2024
-
4.3
MEDIUMCVE-2006-2228
Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals) char... Read more
Affected Products : w-agora- Published: May. 05, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-39375
Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-49976
Missing Authorization vulnerability in WANotifier WANotifier allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WANotifier: from n/a through 2.7.7.... Read more
Affected Products : wanotifier- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-49972
Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy allows Cross Site Request Forgery. This issue affects TM Replace Howdy: from n/a through 1.4.2.... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2016-0232
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.... Read more
Affected Products : financial_transaction_manager- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-47298
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account status... Read more
Affected Products : terminal_handler- Published: Jun. 23, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-3511
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a s... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2021-26998
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disab... Read more
Affected Products : cloud_manager- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2162
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoSh... Read more
Affected Products : flashair- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-30747
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with net... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jul. 15, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2022-3173
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.... Read more
Affected Products : snipe-it- Published: Sep. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0208
IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors.... Read more
Affected Products : websphere_commerce- Published: Mar. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-31921
Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder allows Cross Site Request Forgery. This issue affects WP Ultimate Tours Builder: from n/a through 1.055.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2021-37554
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.... Read more
Affected Products : youtrack- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-4756
Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter.... Read more
Affected Products : php-daily- Published: Oct. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-48079
Missing Authorization vulnerability in Metagauss ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ProfileGrid : from n/a through 5.9.5.1.... Read more
Affected Products : profilegrid- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-0373
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validation on the 'save_vi... Read more
Affected Products : views_for_wpforms- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-32587
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the... Read more
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-41273
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test ema... Read more
Affected Products : panel- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024