Latest CVE Feed
-
4.3
MEDIUMCVE-2014-2080
Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter.... Read more
Affected Products : modx_revolution- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2471
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.... Read more
Affected Products : ilearning- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2313
A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : azure_key_vault- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2310
Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : ansible- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4601
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.... Read more
Affected Products : rational_quality_manager- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-26506
An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users. The accessed files were not visible by the low privileged users in th... Read more
Affected Products : marmind- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-5944
In BIG-IQ 7.1.0, accessing the DoS Summary events and DNS Overview pages in the BIG-IQ system interface returns an error message due to disabled Grafana reverse proxy in web service configuration. F5 has done further review of this vulnerability and has r... Read more
Affected Products : big-iq_centralized_management- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4484
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system. IBM X-Force ID: 181858.... Read more
Affected Products : urbancode_deploy- Published: Nov. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6273
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization C... Read more
Affected Products : s\/4_hana_fiori_ui_for_general_ledger_accounting- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5465
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.... Read more
Affected Products : gitlab- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6299
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.... Read more
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6316
SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.... Read more
- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4579
IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 167236.... Read more
- Published: Aug. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-15731
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefe... Read more
Affected Products : engines- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-25774
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to... Read more
- Published: Sep. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4405
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484.... Read more
Affected Products : verify_gateway- Published: Jul. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4410
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET request to read attachments on the server that they should not have access to. IBM X-Force ID: 179539.... Read more
- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-19980
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occur... Read more
- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6233
SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-39586
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024