Latest CVE Feed
-
4.3
MEDIUMCVE-2021-42663
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the we... Read more
Affected Products : online_event_booking_and_reservation_system- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29769
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-2377
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4162
archivy is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : archivy- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-6954
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.... Read more
Affected Products : buddypress- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-29192
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.... Read more
Affected Products : silverwaregames- Published: Apr. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-6918
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.... Read more
Affected Products : bigtree_cms- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-48393
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.... Read more
Affected Products : webitr_attendance_system- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-41273
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test ema... Read more
Affected Products : panel- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-10299
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access v... Read more
Affected Products : agile_product_lifecycle_management_framework agile_plm agile_product_lifecycle_management- Published: Oct. 19, 2017
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2023-1903
SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data. ... Read more
Affected Products : hcm_fiori_app_my_forms- Published: Apr. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-8401
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-... Read more
Affected Products : ht_mega- Published: Jul. 31, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2018-12576
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34765
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-b... Read more
Affected Products : nexus_insights- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUM- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2022-24694
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)... Read more
Affected Products : mahara- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-31293
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing ... Read more
Affected Products : cash_point_\&_transport_optimizer- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-8301
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnera... Read more
Affected Products : flexcube_universal_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8308
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows... Read more
Affected Products : flexcube_private_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-1922
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This make... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024