Latest CVE Feed
-
4.3
MEDIUMCVE-2021-38020
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2022
An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on ... Read more
Affected Products : gitlab- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-44394
MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This issue has been addressed in commit `65... Read more
Affected Products : mantisbt- Published: Oct. 16, 2023
- Modified: Aug. 11, 2025
-
4.3
MEDIUMCVE-2017-5524
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.... Read more
Affected Products : plone- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-22240
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled... Read more
Affected Products : gitlab- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22198
An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.... Read more
Affected Products : gitlab- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21636
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : team_foundation_server- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-5451
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addr... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-7144
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-8632
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property av... Read more
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-23969
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-5395
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android.... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-8555
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Secur... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-3097
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and... Read more
Affected Products : tivoli_federated_identity_manager- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-20474
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses a... Read more
Affected Products : manageengine_remote_access_plus- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-58458
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attac... Read more
Affected Products : git_client- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2023-40536
Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products :- Published: May. 16, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-54732
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages allows Cross Site Request Forgery. This issue affects WPDM – Premium Packages: from n/a through 6.0.2.... Read more
Affected Products : premium_packages_-_sell_digital_products_securely- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2020-25950
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.... Read more
Affected Products : advanced_webhost_billing_system- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43229
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Search Analytics: from n/a through 1.4.9.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024