Latest CVE Feed
-
4.3
MEDIUMCVE-2025-52719
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss ProfileGrid allows Retrieve Embedded Sensitive Data. This issue affects ProfileGrid : from n/a through 5.9.5.2.... Read more
Affected Products : profilegrid- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2023-36652
A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.... Read more
Affected Products : cryptospike- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2021-46600
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2884
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.... Read more
Affected Products : world\'s_tallest_buildings- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-32226
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accepted by the server, so that instead ... Read more
Affected Products : rocket.chat- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2024-34427
Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Favorite Posts.This issue affects WP Favorite Posts: from n/a through 1.6.8. ... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3006
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which tr... Read more
Affected Products : maxthon_browser- Published: Aug. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-38329
A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, potentially causing the administrator to perform unintended actions on an affected system. The vulnerability could allow attackers to mod... Read more
Affected Products : shopxian_cms- Published: Sep. 13, 2022
- Modified: Mar. 28, 2025
-
4.3
MEDIUMCVE-2021-25930
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerab... Read more
- Published: May. 20, 2021
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2019-0305
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or doma... Read more
Affected Products : netweaver_process_integration- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6611
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-mi... Read more
- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3056
Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN 2.0rc4, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the path parameter.... Read more
Affected Products : websvn- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-12869
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or user... Read more
Affected Products : ragflow- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2013-6969
The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.... Read more
Affected Products : webex_training_center- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-11852
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions... Read more
Affected Products : element_pack- Published: Dec. 22, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2009-2917
Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.... Read more
Affected Products : mpeg_encoder- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-41961
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join th... Read more
Affected Products : bigbluebutton- Published: Dec. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2240
Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : free-sw_leger- Published: Jun. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3516
Multiple cross-site scripting (XSS) vulnerabilities in files generated by Adobe Presenter 6 and 7 before 7.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) viewer.swf and (2) loadflash.js, a different... Read more
Affected Products : presenter- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-4251
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.... Read more
Affected Products : eventprime- Published: Oct. 31, 2023
- Modified: Apr. 22, 2025