Latest CVE Feed
-
4.3
MEDIUMCVE-2021-24800
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.... Read more
Affected Products : dw_question_\&_answer- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3966
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via (1) a certain referrer field in usercp2.php, (2) a certain location field in inc/functions_onl... Read more
Affected Products : mybb- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-24749
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.... Read more
Affected Products : url_shortify- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-39884
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.... Read more
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6836
The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multip... Read more
Affected Products : funnel_builder- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2615
Multiple cross-site scripting (XSS) vulnerabilities in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) page_menu and (2) description parameters in an edit_page action.... Read more
Affected Products : grafik_cms- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-5449
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.... Read more
Affected Products : nextcloud_server- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4711
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-lev... Read more
Affected Products : royal_elementor_addons- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4163
IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view. IBM X-Force ID: 158696.... Read more
Affected Products : storediq- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4234
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force ID: ... Read more
Affected Products : pureapplication_system- Published: Jun. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4630
Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4631
Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) countrycode parameter to contact.asp, USERNAME parameter to (2) gateway.asp and (3) cart.asp, and the s... Read more
Affected Products : pilot_cart- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-4377
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.... Read more
- Published: Jun. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4616
IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The ... Read more
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-27661
Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow.... Read more
Affected Products : garoon- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3775
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.... Read more
Affected Products : ilearning- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-5959
A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak password recovery. The... Read more
- Published: Nov. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4743
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-3345
Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and earlier, allows remote attackers to inject arbitrary web script or HTML via a chat line.... Read more
Affected Products : alipager- Published: Jul. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-1000514
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result in CSRF admins to delete boxes. This vulnerability appears to have been fixed in 3.6.x.... Read more
Affected Products : limesurvey- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024