Latest CVE Feed
-
4.3
MEDIUMCVE-2010-2091
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive informa... Read more
- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0938
Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action.... Read more
Affected Products : todoo_forum- Published: Mar. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2106
Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof the URL bar via vectors involving unload event handlers.... Read more
Affected Products : chrome- Published: May. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0913
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-11373
The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : connexion_logs- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2022-1425
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read mes... Read more
Affected Products : wpqa_builder- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-44837
An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an admin user regarding the risk creation information in the /risque/administration/referentiel/json/create/categorie endpoint, using the id... Read more
Affected Products : delta_rm- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2253
Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : mahara- Published: Nov. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-39927
Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configure... Read more
Affected Products : gitlab- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1417
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Me... Read more
Affected Products : gitlab- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42568
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.... Read more
Affected Products : nexus_repository_manager- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39931
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39857
Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage t... Read more
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39918
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be ac... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37867
Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.... Read more
Affected Products : mattermost_boards- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1004
Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.... Read more
Affected Products : otrs- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39871
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.... Read more
Affected Products : gitlab- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1498
Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39904
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator t... Read more
Affected Products : gitlab- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-42009
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an ar... Read more
Affected Products : traffic_control- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024