Latest CVE Feed
-
4.3
MEDIUMCVE-2022-4184
Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-40817
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issu... Read more
Affected Products : zammad- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2009-2967
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959.... Read more
Affected Products : buildbot- Published: Aug. 26, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3070
Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes.... Read more
Affected Products : nusoap- Published: Sep. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-42807
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key... Read more
Affected Products : macos- Published: Jun. 23, 2023
- Modified: Dec. 06, 2024
-
4.3
MEDIUMCVE-2022-3435
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate t... Read more
- Published: Oct. 08, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-41230
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as wel... Read more
Affected Products : build-publisher- Published: Sep. 21, 2022
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2022-41233
Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts p... Read more
Affected Products : rundeck- Published: Sep. 21, 2022
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2009-0023
The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the ... Read more
- Published: Jun. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-41251
A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : apprenda- Published: Sep. 21, 2022
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2022-41263
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise re... Read more
Affected Products : business_objects_business_intelligence_platform- Published: Dec. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-47148
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.... Read more
Affected Products : woocommerce_pdf_invoices\&_packing_slips- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-48309
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.... Read more
Affected Products : connect- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
4.3
MEDIUMCVE-2022-3447
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-40316
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.... Read more
- Published: Sep. 30, 2022
- Modified: May. 20, 2025
-
4.3
MEDIUMCVE-2013-1955
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php and (2) datePicker.php in Easy PHP Calendar 6.x and 7.x before 7.0.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : easy_php_calendar- Published: Jul. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-4182
Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0141
Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to t... Read more
Affected Products : epolicy_orchestrator- Published: May. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10963
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.... Read more
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-17475
Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024