Latest CVE Feed
-
4.3
MEDIUMCVE-2023-2896
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possible for unauthenti... Read more
Affected Products : wp_easycart- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-16633
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.... Read more
Affected Products : joomla\!- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-29294
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerabilit... Read more
- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2546
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: SQL Extensions). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vu... Read more
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-26434
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavaila... Read more
- Published: Jun. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1849
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.... Read more
Affected Products : cpanel- Published: Mar. 24, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-22728
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content aut... Read more
Affected Products : framework- Published: Apr. 26, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-26433
When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavaila... Read more
- Published: Jun. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-30946
A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the issue including t... Read more
Affected Products : foundry_issues- Published: Jun. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-3031
Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random informa... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-2632
Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attac... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2579
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT... Read more
Affected Products : webcenter_sites- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2435
Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.... Read more
Affected Products : hrms- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-22134
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document.... Read more
Affected Products : elasticsearch communications_cloud_native_core_automated_test_suite elasticsearch- Published: Mar. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-26273
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134.... Read more
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-6790
An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests... Read more
Affected Products : gitlab- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22176
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests... Read more
Affected Products : gitlab- Published: Mar. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1735
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : sympa- Published: Aug. 21, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-29111
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confi... Read more
Affected Products : application_interface_framework- Published: Apr. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22177
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.... Read more
Affected Products : gitlab- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024