Latest CVE Feed
-
4.3
MEDIUMCVE-2014-9444
Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.... Read more
Affected Products : frontend_uploader- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-25451
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-26031
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).... Read more
Affected Products : zammad- Published: Dec. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6599
The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.11. This makes it possible for authenticated att... Read more
Affected Products :- Published: Jul. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2049
The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message.... Read more
Affected Products : mail_server- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5076
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in protected/views/admin/formEditor.php; the (2) importId parameter in protected... Read more
Affected Products : x2crm- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6196
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging... Read more
- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-43340
Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.... Read more
Affected Products : advanced_form_integration- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
4.3
MEDIUMCVE-2021-42116
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users,... Read more
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41132
Missing Authorization vulnerability in ShapedPlugin LLC Category Slider for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Category Slider for WooCommerce: from n/a through 1.4.15.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2022-27846
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create or modify slider.... Read more
Affected Products : yoo_slider- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-9430
Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via the COMMENT parameter in an Add action.... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-32583
Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vectors.... Read more
Affected Products : office- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-39744
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2024-10329
The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, w... Read more
Affected Products : ultimate_bootstrap_elements_for_elementor- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-32525
Missing Authorization vulnerability in Theme My Login.This issue affects Theme My Login: from n/a through 7.1.6. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-39961
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could... Read more
- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1070
Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parame... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-4819
Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : txx_cms- Published: Sep. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-3846
Cross-site scripting (XSS) vulnerability in index.php in PHP-pastebin 2.1 allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : php-pastebin- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025