Latest CVE Feed
-
4.3
MEDIUMCVE-2025-49550
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security ... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-5477
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)... Read more
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1208
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.... Read more
Affected Products : vpn-1_utm_edge_w_embedded_ngx- Published: Mar. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1211
Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in calendar.php and (2) the category parameter in calendar_search.php. NOTE: the provenance of this... Read more
Affected Products : bosdates- Published: Mar. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1045
Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter.... Read more
Affected Products : opencms- Published: Feb. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-22643
Missing Authorization vulnerability in FameThemes OnePress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OnePress: from n/a through 2.3.11.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1202
Cross-site scripting (XSS) vulnerability in the web management interface in Adobe LiveCycle Workflow 6.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : livecycle_workflow- Published: Mar. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-1495
IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation.... Read more
- Published: May. 03, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-27146
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed ... Read more
Affected Products : matrix_irc_bridge- Published: Feb. 25, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-4316
Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 202... Read more
Affected Products : devolutions_server- Published: May. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-52919
In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-8482
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers,... Read more
Affected Products : simple_local_avatars- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1061
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view... Read more
Affected Products : sniplets_plugin- Published: Feb. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.... Read more
Affected Products : moodle- Published: Apr. 25, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-3452
The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' function in all versions up to, and including, 2.3.9. This... Read more
Affected Products : secupress- Published: Apr. 29, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.... Read more
Affected Products : moodle- Published: Apr. 25, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24982
Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-49967
Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder allows Cross Site Request Forgery. This issue affects Live Sports Streamthunder: from n/a through 2.1.... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-49969
Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zara 4 Image Compression: from n/a through 1.2.17.2.... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-49968
Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget allows Cross Site Request Forgery. This issue affects XML Travel Portal Widget: from n/a through 2.0.... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery