Latest CVE Feed
-
4.3
MEDIUMCVE-2025-24397
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text... Read more
Affected Products : gitlab- Published: Jan. 22, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-37508
Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Construction Landing Page allows Cross Site Request Forgery.This issue affects Construction Landing Page: from n/a through 1.3.5.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-4580
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : file_provider- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-37493
Cross-Site Request Forgery (CSRF) vulnerability in SKT Themes Posterity allows Cross Site Request Forgery.This issue affects Posterity: from n/a through 3.3.... Read more
Affected Products : posterity- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-38754
Cross-Site Request Forgery (CSRF) vulnerability in Tagbox Taggbox allows Cross Site Request Forgery.This issue affects Taggbox: from n/a through 3.3.... Read more
Affected Products : taggbox- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2010-1899
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repe... Read more
- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0684
Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter.... Read more
Affected Products : itechclassifieds- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-4083
The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement in an archive of debugging information, which might all... Read more
Affected Products : sos- Published: Feb. 17, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-1155
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site.... Read more
- Published: May. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6165
Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6114.... Read more
Affected Products : silverlight- Published: Dec. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-3985
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after d... Read more
Affected Products : firefox thunderbird ubuntu_linux linux_enterprise_server seamonkey linux_enterprise_desktop- Published: Oct. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-4020
RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a ... Read more
- Published: Aug. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-8283
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Types.... Read more
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2963
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonst... Read more
Affected Products : paperclip- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-1588
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.... Read more
- Published: Jul. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-4101
The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and applicatio... Read more
Affected Products : wireshark- Published: Nov. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0372
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 be... Read more
- Published: Nov. 24, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2909
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker wit... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-38394
Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, su... Read more
Affected Products :- Published: Jun. 16, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9710
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024