Latest CVE Feed
-
4.3
MEDIUMCVE-2025-30926
Missing Authorization vulnerability in KingAddons.com King Addons for Elementor. This issue affects King Addons for Elementor: from n/a through 24.12.58.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2013-1497
Unspecified vulnerability in the Oracle COREid Access component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to WebGate - WebServer plugin.... Read more
Affected Products : fusion_middleware- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5608
Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.... Read more
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-31410
Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Church Donation allows Cross Site Request Forgery.This issue affects WP Church Donation: from n/a through 1.7.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-7048
The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthentica... Read more
Affected Products : my_sticky_bar- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025
-
4.3
MEDIUMCVE-2025-49250
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase allows Code Injection. This issue affects Team Showcase: from n/a through n/a.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2022-26054
Operation restriction bypass vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Link.... Read more
Affected Products : garoon- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4883
Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a similar issue to CVE-2007-4828.... Read more
Affected Products : mediawiki- Published: Sep. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5430
Mozilla Thunderbird 2.0.14 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which might allow remote attackers to cause a denial of servic... Read more
Affected Products : thunderbird- Published: Dec. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-27576
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0366
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible f... Read more
Affected Products : starbox- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-5103
Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe. ... Read more
- Published: Oct. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6955
Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.... Read more
Affected Products : opera_browser- Published: Jan. 29, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2897
Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Applica... Read more
- Published: Oct. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-8006
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.... Read more
Affected Products : isb8320-e_high-definition_ip-only_dvr- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-25783
Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2884
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.... Read more
Affected Products : world\'s_tallest_buildings- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-48016
OpenFlow discovery protocol can exhaust resources because it is not rate limited... Read more
Affected Products :- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2024-0796
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce valida... Read more
Affected Products : woot- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-9929
A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024