Latest CVE Feed
-
4.3
MEDIUMCVE-2024-43356
Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0.... Read more
Affected Products : oik- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
4.3
MEDIUMCVE-2014-8024
The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789.... Read more
Affected Products : jabber_guest- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-25451
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38372
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.... Read more
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2195
Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name... Read more
- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-25036
IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.... Read more
Affected Products : cognos_controller- Published: Dec. 03, 2024
- Modified: Dec. 11, 2024
-
4.3
MEDIUMCVE-2023-6070
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where... Read more
Affected Products : enterprise_security_manager- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21661
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : kubernetes- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6824
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) w... Read more
Affected Products : php_icalendar- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-2136
Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Physical network name to the Zone wizard; (2) New network name, (3) instance name, or (4) group... Read more
Affected Products : cloudstack- Published: Aug. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-34439
Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a through 1.14.4. ... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-9538
The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-l... Read more
Affected Products : woolentor_-_woocommerce_elementor_addons_\+_builder- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-3664
The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible fo... Read more
Affected Products :- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-6386
Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : z1exchange- Published: Mar. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-32525
Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33324
The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the ... Read more
- Published: Aug. 03, 2021
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2024-25150
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users ... Read more
- Published: Feb. 20, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2021-32787
Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The site-admin area can be accessed by regular users and all information and features are properly protected except for daily usage ... Read more
Affected Products : sourcegraph- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-7182
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker... Read more
Affected Products : wp_go_maps- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-7938
P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the lack of permission validation. An attacker tricks a user into installing a malicious application on the smart phone, and the applicatio... Read more
- Published: Sep. 04, 2018
- Modified: Nov. 21, 2024