Latest CVE Feed
-
4.3
MEDIUMCVE-2021-33334
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Acces... Read more
- Published: Aug. 03, 2021
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2022-43698
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.... Read more
Affected Products : ox_app_suite- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025
-
4.3
MEDIUMCVE-2024-45203
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a... Read more
Affected Products : \@cosme- Published: Sep. 09, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2023-6492
The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.13. This is due to missing or incorrect nonce validation in the 'admin_notices' hook found in ... Read more
Affected Products :- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11918
The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_action AJAX actions in all versions up to, and including, 2.0.0. This makes ... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
4.3
MEDIUMCVE-2023-0499
The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack... Read more
Affected Products : quickswish- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
4.3
MEDIUMCVE-2022-1695
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.... Read more
Affected Products : wp_simple_adsense_insertion- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-44548
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.... Read more
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2023-34085
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request ... Read more
Affected Products : pingfederate- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-30155
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tu... Read more
Affected Products : tuleap- Published: Mar. 31, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-31385
Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128. ... Read more
- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-17143
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : phantompdf- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-32273
As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.... Read more
Affected Products : metadefender- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3601
The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.... Read more
Affected Products : simple_author_box- Published: Aug. 14, 2023
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2023-6070
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where... Read more
Affected Products : enterprise_security_manager- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22334
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391.... Read more
Affected Products : robotic_process_automation- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-45369
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.... Read more
Affected Products : plugin_for_google_reviews- Published: Nov. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22391
IBM Aspera High-Speed Transfer 4.3.1 and earlier could allow an authenticated user to obtain information from non sensitive operating system files that they should not have access to. IBM X-Force ID: 222059.... Read more
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6824
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) w... Read more
Affected Products : php_icalendar- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-3664
The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible fo... Read more
Affected Products :- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024