Latest CVE Feed
-
4.3
MEDIUMCVE-2024-43105
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2017-1000390
Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.... Read more
Affected Products : multijob- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-0888
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of informat... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2019-1563
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any... Read more
Affected Products : openssl- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3265
Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the ven... Read more
Affected Products : opera_browser- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-9553
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9488
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2... Read more
Affected Products : debian_linux weblogic_server peoplesoft_enterprise_peopletools siebel_ui_framework data_integrator retail_customer_management_and_segmentation_foundation primavera_unifier retail_predictive_application_server retail_bulk_data_integration retail_xstore_point_of_service +36 more products- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-0920
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respectiv... Read more
Affected Products : gitlab- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33689
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.... Read more
Affected Products : netweaver_application_server_java- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21464
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21533
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally access to the same subset of job d... Read more
Affected Products : wyse_management_suite- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-13717
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2374
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites ... Read more
Affected Products : drupal- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-8720
An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be co... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-2162
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plug-in). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with network acce... Read more
Affected Products : active_iq_unified_manager mysql oncommand_insight oncommand_workflow_automation snapcenter mysql_server- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29959
When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microph... Read more
Affected Products : firefox- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-15920
An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.... Read more
- Published: Sep. 04, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1002024
Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.... Read more
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-21438
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.... Read more
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2043
nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.... Read more
Affected Products : firefox- Published: Jun. 12, 2009
- Modified: Apr. 09, 2025