Latest CVE Feed
-
4.3
MEDIUMCVE-2021-4364
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authentica... Read more
Affected Products : jobsearch_wp_job_board- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2092
Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the o... Read more
Affected Products : cms_made_simple- Published: Mar. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-27661
Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow.... Read more
Affected Products : garoon- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4307
The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack... Read more
Affected Products : lock_user_account- Published: Sep. 11, 2023
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2010-2292
Cross-site scripting (XSS) vulnerability in the Ping tools web interface in Dlink Di-604 router allows remote attackers to inject arbitrary web script or HTML via the IP field.... Read more
Affected Products : di-604- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-46600
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-23689
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the ... Read more
- Published: Sep. 06, 2022
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2016-5945
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4571
Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter.... Read more
Affected Products : vn-calendar- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-42067
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not ... Read more
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-8322
Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows low privileged attacker w... Read more
Affected Products : flexcube_core_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2020-4315
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the u... Read more
Affected Products : business_automation_content_analyzer_on_cloud- Published: Sep. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-2846
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticate... Read more
Affected Products : calendar_event_multi_view- Published: Aug. 16, 2022
- Modified: Apr. 15, 2025
-
4.3
MEDIUMCVE-2023-50333
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names. ... Read more
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32112
Cross-Site Request Forgery (CSRF) vulnerability in Leadinfo leadinfo. The patch was released under the same version which was reported as vulnerable. We consider the current version as vulnerable.This issue affects Leadinfo: from n/a through 1.0. ... Read more
Affected Products :- Published: Apr. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36382
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).... Read more
Affected Products : devolutions_server- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6310
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.... Read more
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3308
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.... Read more
- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-3200
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged ... Read more
Affected Products : mstore_api- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0695
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.... Read more
Affected Products : basic-cms- Published: Feb. 23, 2010
- Modified: Apr. 11, 2025