Latest CVE Feed
-
4.3
MEDIUMCVE-2025-31596
Missing Authorization vulnerability in Chatwee Chat by Chatwee allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Chat by Chatwee: from n/a through 2.1.3.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-22164
In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacke... Read more
Affected Products : enterprise_security- Published: Jan. 09, 2024
- Modified: Jun. 03, 2025
-
4.3
MEDIUMCVE-2024-0942
A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the atta... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30526
Cross-Site Request Forgery (CSRF) vulnerability in Easy Social Feed.This issue affects Easy Social Feed: from n/a through 6.5.6. ... Read more
Affected Products : easy_social_feed- Published: Mar. 31, 2024
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2015-0269
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.... Read more
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-6574
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 6.1.0.3 allows remote attackers to affect integrity via unknown vectors related to Testing Protocol Library.... Read more
Affected Products : supply_chain_products_suite- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-28909
Cross-Site Request Forgery (CSRF) vulnerability in edwardw WP No-Bot Question allows Cross Site Request Forgery. This issue affects WP No-Bot Question: from n/a through 0.1.7.... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2007-2011
Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : deskpro- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-1888
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in anoth... Read more
- Published: Feb. 29, 2024
- Modified: May. 12, 2025
-
4.3
MEDIUMCVE-2023-32672
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by... Read more
Affected Products : superset- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-45874
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).... Read more
Affected Products : couchbase_server- Published: Feb. 29, 2024
- Modified: Mar. 26, 2025
-
4.3
MEDIUMCVE-2024-35636
Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11.... Read more
Affected Products :- Published: Jun. 01, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3631
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack... Read more
Affected Products : hl_twitter- Published: May. 15, 2024
- Modified: May. 15, 2025
-
4.3
MEDIUMCVE-2023-30703
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.... Read more
Affected Products : members- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2035
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for ... Read more
- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-26948
Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.... Read more
Affected Products :- Published: Feb. 25, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2022-4426
The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbit... Read more
Affected Products : mautic_integration_for_woocommerce- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-8431
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it pos... Read more
Affected Products : robo_gallery- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2014-8471
CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to conduct replay attacks via unspecified vectors.... Read more
Affected Products : cloud_service_management- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-32226
Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Display product variations dropdown on shop page: from n/a thro... Read more
Affected Products :- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authorization