Latest CVE Feed
-
4.3
MEDIUMCVE-2023-2764
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attacke... Read more
Affected Products : draw_attention- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-29334
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Apr. 28, 2023
- Modified: Feb. 28, 2025
-
4.3
MEDIUMCVE-2020-2519
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attac... Read more
Affected Products : weblogic_server- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-1481
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. This vulnerability is due to insufficient ... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 15, 2024
- Modified: Aug. 04, 2025
-
4.3
MEDIUMCVE-2020-2745
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Federation). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network acces... Read more
Affected Products : access_manager- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-25750
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.... Read more
Affected Products : firefox- Published: Jun. 02, 2023
- Modified: Jan. 09, 2025
-
4.3
MEDIUMCVE-2020-2182
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.... Read more
Affected Products : credentials_binding- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-2902
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Console). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
Affected Products : weblogic_server- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2245
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.... Read more
Affected Products : goollery- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-28708
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and ... Read more
Affected Products : tomcat- Published: Mar. 22, 2023
- Modified: Aug. 07, 2025
-
4.3
MEDIUMCVE-2017-11803
Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Discl... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-1267
A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper restrictions... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2018-2927
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: HTTP data path subsystems). The supported version that is affected is Prior to 8.7.18. Easily exploitable vulnerability allows low privil... Read more
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-26412
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.... Read more
Affected Products : gitlab- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1999
Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.... Read more
Affected Products : php-nuke- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1960
Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.... Read more
Affected Products : protector_system- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-12434
An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disclosure.... Read more
Affected Products : gitlab- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-59034
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin... Read more
Affected Products : indico- Published: Sep. 10, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-2627
The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Do... Read more
Affected Products : kivicare- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10732
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart em... Read more
- Published: Apr. 07, 2019
- Modified: Nov. 21, 2024