Latest CVE Feed
-
4.3
MEDIUMCVE-2021-38378
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.... Read more
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0321
Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.... Read more
Affected Products : jamit_job_board- Published: Jan. 15, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0967
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.... Read more
Affected Products :- Published: Mar. 01, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-6542
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.... Read more
- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34553
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.... Read more
Affected Products : nexus_repository_manager- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-26432
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavaila... Read more
- Published: Jun. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-23688
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the ... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-22731
Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Build Private Store For Woocommerce allows Cross Site Request Forgery.This issue affects Build Private Store For Woocommerce: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify... Read more
Affected Products : manageengine_servicedesk_plus- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3255
Cross-site scripting (XSS) vulnerability in LunarNight Laboratory WebProxy 1.7.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10271
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the prof... Read more
Affected Products : ultimate_member- Published: Jun. 24, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5099
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.... Read more
Affected Products : phpb2b- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4889
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter ... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-30546
Cross-Site Request Forgery (CSRF) vulnerability in boroV Cackle allows Cross Site Request Forgery. This issue affects Cackle: from n/a through 4.33.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2014-8024
The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789.... Read more
Affected Products : jabber_guest- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-44431
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT... Read more
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22702
PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.... Read more
Affected Products : partkeepr- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2295
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.... Read more
Affected Products : rgboard- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-0328
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Librar... Read more
Affected Products : wpcode- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
4.3
MEDIUMCVE-2022-46150
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches, unauthorized users may learn of the existence of hidden tags and that they have been applie... Read more
Affected Products : discourse- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024