Latest CVE Feed
-
4.3
MEDIUMCVE-2021-21492
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.... Read more
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2475
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol do... Read more
Affected Products : toolbar- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-21651
Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain the list of configured profiles.... Read more
Affected Products : s3_publisher- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2492
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.... Read more
Affected Products : groupmax_world_wide_web_desktop- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-2895
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it possible for unauth... Read more
Affected Products : wp_easycart- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41864
Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF7 Database: from n/a through 1.8.0. ... Read more
Affected Products : peprodev_cf7_database- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-30450
rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turne... Read more
Affected Products : redpanda- Published: Apr. 08, 2023
- Modified: Feb. 12, 2025
-
4.3
MEDIUMCVE-2023-30480
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5. ... Read more
Affected Products :- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41865
Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2020-2561
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with ne... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-30530
Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products : consul_kv_builder- Published: Apr. 12, 2023
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2005-0270
Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report pa... Read more
Affected Products : reviewpost_php_pro- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUM- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-32988
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : azure_vm_agents- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
4.3
MEDIUMCVE-2005-0264
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.... Read more
Affected Products : owl_intranet_engine- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-29401
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition heade... Read more
Affected Products : gin- Published: Jun. 08, 2023
- Modified: Jan. 06, 2025
-
4.3
MEDIUMCVE-2022-23442
An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other ... Read more
Affected Products : fortios- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-32982
Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system... Read more
Affected Products : ansible- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
4.3
MEDIUMCVE-2023-32978
A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.... Read more
Affected Products : lightweight_directory_access_protocol- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
4.3
MEDIUMCVE-2023-32599
Missing Authorization vulnerability in Bill Minozzi reCAPTCHA for all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects reCAPTCHA for all: from n/a through 1.22.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024