Latest CVE Feed
-
4.3
MEDIUMCVE-2015-0381
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.... Read more
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9272
The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.... Read more
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0369
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to AX/HI Web UI.... Read more
Affected Products : siebel_crm- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0344
Cross-site scripting (XSS) vulnerability in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : connect- Published: Jun. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2349
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.... Read more
Affected Products : superwebmailer- Published: Mar. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-4941
IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.... Read more
Affected Products : edge_application_manager- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31235
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5. ... Read more
Affected Products : wordpress_comments_import_and_export- Published: Apr. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2025
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an... Read more
Affected Products : websphere_extreme_scale- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-32001
SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause LookupSubjects to only return the subjects fo... Read more
Affected Products : spicedb- Published: Apr. 10, 2024
- Modified: Sep. 02, 2025
-
4.3
MEDIUMCVE-2024-31934
Cross-Site Request Forgery (CSRF) vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.9. ... Read more
Affected Products : link_whisper_free- Published: Apr. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31923
Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page.This issue affects Feather Login Page: from n/a through 1.1.5. ... Read more
Affected Products : custom_login_page_\|_temporary_users_\|_rebrand_login_\|_login_captcha- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-3458
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors related to CORBA.... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9253
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/... Read more
- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-31922
Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3714
The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.... Read more
Affected Products : safari- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-31894
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.... Read more
Affected Products : app_connect_enterprise- Published: May. 22, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2015-1248
The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: U... Read more
- Published: Apr. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-31897
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta... Read more
Affected Products : cloud_pak_for_business_automation- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2413
Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2054
CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762S, and 763S allows remote attackers to inject arbitrary headers via CRLF sequences in the save parameter.... Read more
Affected Products : sierra_wireless_aircard_760s sierra_wireless_aircard_762s sierra_wireless_aircard_763s- Published: Feb. 23, 2015
- Modified: Apr. 12, 2025