Latest CVE Feed
-
4.3
MEDIUMCVE-2022-4872
The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'... Read more
Affected Products : chained_products- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2007-4199
Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain NTFS files via a malformed NTFS image that triggers (1) dereference of a certain integ... Read more
Affected Products : the_slueth_kit- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-4770
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). ... Read more
- Published: Apr. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2002-1893
Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.... Read more
Affected Products : argosoft_mail_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-0225
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.... Read more
Affected Products : samba- Published: Apr. 03, 2023
- Modified: Feb. 18, 2025
-
4.3
MEDIUMCVE-2023-0583
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to ch... Read more
Affected Products : vk_blocks- Published: Jun. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-0293
The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with subsc... Read more
Affected Products : mediamatic- Published: Jan. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1338
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated at... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1336
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated a... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1375
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with ... Read more
Affected Products : wp_fastest_cache- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1335
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticat... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-6044
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-1779
Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limite... Read more
- Published: Jun. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1939
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface... Read more
Affected Products : remote_desktop_manager- Published: Apr. 11, 2023
- Modified: Feb. 10, 2025
-
4.3
MEDIUMCVE-2023-1555
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.... Read more
Affected Products : gitlab- Published: Sep. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1924
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1923
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This mak... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1930
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1870
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the saveLang function. This makes it possible for unauthenticated attackers t... Read more
Affected Products : yourchannel- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1919
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it p... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024