Latest CVE Feed
-
4.3
MEDIUMCVE-2024-3936
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and includ... Read more
Affected Products : the_post_grid- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47059
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Inva... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Feb. 27, 2025
-
4.3
MEDIUMCVE-2020-14600
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-52224
Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43032
autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.... Read more
Affected Products : autman- Published: Aug. 23, 2024
- Modified: Sep. 03, 2025
-
4.3
MEDIUMCVE-2022-2369
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin... Read more
Affected Products : yaysmtp- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4833
IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to l... Read more
Affected Products : websphere_application_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-35671
Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3856
Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party informati... Read more
Affected Products : twilight_cms- Published: Nov. 04, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-4331
Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary web script or HTML via the src parameter.... Read more
Affected Products : octavocms- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-29433
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource e... Read more
Affected Products : sydent- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-7314
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.... Read more
Affected Products : gollum- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-6307
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.... Read more
Affected Products : basis- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20630
Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6361
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE files received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is ca... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0358
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2020-6348
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0974
Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.... Read more
Affected Products : bttlxeforum- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-1003010
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.... Read more
- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-6400
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) search.php. NOTE: some of these details are obtained from third party info... Read more
Affected Products : refbase- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025