Latest CVE Feed
-
4.3
MEDIUMCVE-2024-49798
IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more
Affected Products : applinx- Published: Feb. 06, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2008-1179
Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these... Read more
Affected Products : centreon- Published: Mar. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-49977
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager allows Cross Site Request Forgery. This issue affects WP Inventory Manager: from n/a through 2.3.4.... Read more
Affected Products : wp_inventory_manager- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-1208
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.... Read more
Affected Products : vpn-1_utm_edge_w_embedded_ngx- Published: Mar. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-2527
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.... Read more
Affected Products : mattermost_server- Published: May. 15, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1178
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.... Read more
Affected Products : centreon- Published: Mar. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1183
Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax Live Help (CSLH) before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) livehelp.php, (2) user_questions.php, and (3) leavemessage.... Read more
Affected Products : crafty_syntax_live_help- Published: Mar. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-49794
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : applinx- Published: Feb. 06, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-27425
Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.... Read more
- Published: Mar. 04, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-47609
Cross-Site Request Forgery (CSRF) vulnerability in easymebiz EasyMe Connect allows Cross Site Request Forgery. This issue affects EasyMe Connect: from n/a through 3.0.3.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-1229
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via the editor parameter, a different vector than CVE-2007-5120.b.... Read more
Affected Products : jspwiki- Published: Mar. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-7195
The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.... Read more
Affected Products : wp-reply_notify- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-22643
Missing Authorization vulnerability in FameThemes OnePress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OnePress: from n/a through 2.3.11.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-57160
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.... Read more
- Published: Jan. 16, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-5713
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for au... Read more
Affected Products : system_dashboard- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-20956
Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1172
Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages.... Read more
- Published: Mar. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-27436
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a posted bank sta... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-5721
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024