Latest CVE Feed
-
4.3
MEDIUMCVE-2019-4214
IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.... Read more
Affected Products : smartcloud_analytics_log_analysis- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-19411
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific... Read more
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6772
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking... Read more
Affected Products : splunk- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4485
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against ... Read more
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5465
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.... Read more
Affected Products : gitlab- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10482
CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.... Read more
Affected Products : phpkb- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10487
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.... Read more
Affected Products : phpkb- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10499
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.... Read more
Affected Products : phpkb- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10659
Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain.... Read more
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-19677
arxes-tolina 3.0.0 allows User Enumeration.... Read more
Affected Products : arxes-tolina- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-13512
Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an attacker to read limited information from the device.... Read more
Affected Products : frenic_loader- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10901
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4286
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.... Read more
Affected Products : maximo_anywhere- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9387
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.... Read more
Affected Products : mahara- Published: Apr. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-12101
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.... Read more
Affected Products : xt-commerce- Published: Apr. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2184
A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.... Read more
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2186
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.... Read more
Affected Products : amazon_ec2- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4446
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.... Read more
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-15412
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.... Read more
- Published: Jun. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4173
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes ... Read more
- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024