Latest CVE Feed
-
4.3
MEDIUMCVE-2019-18463
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).... Read more
Affected Products : gitlab- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-19091
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.... Read more
Affected Products : esoms- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2570
Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.... Read more
Affected Products : php_font_lib- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-49440
Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master allows Cross Site Request Forgery. This issue affects WP Security Master: from n/a through 1.0.2.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-6617
The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.... Read more
Affected Products : ffmpeg- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6615
The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dialog without text.... Read more
Affected Products : ffmpeg- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-49435
Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass allows Cross Site Request Forgery. This issue affects Wp Easy Allopass: from n/a through 4.1.1.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-13216
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it ... Read more
Affected Products : ht_event- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2008-0720
Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other compon... Read more
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-39434
Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Avatar: from n/a through 0.1.4.... Read more
Affected Products : avatar- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22681
Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1.... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22260
Missing Authorization vulnerability in Pixelite Meta Tag Manager. This issue affects Meta Tag Manager: from n/a through 3.1.... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-3509
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must ha... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2011-3374
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.... Read more
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-39438
Cross-Site Request Forgery (CSRF) vulnerability in momen2009 Theme Changer allows Cross Site Request Forgery. This issue affects Theme Changer: from n/a through 1.3.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2011-2192
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI r... Read more
- Published: Jul. 07, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-23108
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.... Read more
Affected Products : firefox- Published: Jan. 11, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2008-0617
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the gue... Read more
Affected Products : dmsguestbook- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-4580
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : file_provider- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2011-2381
CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attach... Read more
Affected Products : bugzilla- Published: Aug. 09, 2011
- Modified: Apr. 11, 2025