Latest CVE Feed
-
4.3
MEDIUMCVE-2025-30764
Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.... Read more
- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2020-16197
An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use.... Read more
- Published: Aug. 25, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-30805
Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible Cookies allows Cross Site Request Forgery. This issue affects Flexible Cookies: from n/a through 1.1.8.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-30842
Cross-Site Request Forgery (CSRF) vulnerability in pixolette Christmas Panda allows Cross Site Request Forgery. This issue affects Christmas Panda: from n/a through 1.0.4.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-30823
Cross-Site Request Forgery (CSRF) vulnerability in Boone Gorges Anthologize allows Cross Site Request Forgery. This issue affects Anthologize: from n/a through 0.8.2.... Read more
Affected Products : anthologize- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2020-4484
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system. IBM X-Force ID: 181858.... Read more
Affected Products : urbancode_deploy- Published: Nov. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-14313
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories with... Read more
Affected Products : quay- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-11786
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.... Read more
Affected Products : odoo- Published: Dec. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-22673
Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.... Read more
Affected Products : ean_for_woocommerce- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2010-5186
The Antivirus component in Comodo Internet Security before 4.1.150349.920 allows remote attackers to cause a denial of service (application crash) via a crafted file.... Read more
Affected Products : comodo_internet_security- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-20154
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.... Read more
Affected Products : wp_maintenance_mode- Published: Dec. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-1003036
A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM age... Read more
Affected Products : azure_vm_agents- Published: Mar. 08, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-4420
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Tes... Read more
Affected Products : opsview- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4587
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu.... Read more
- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1834
Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-ad... Read more
Affected Products : cms_tree_page_view- Published: Apr. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4550
The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IP... Read more
Affected Products : adaptive_security_appliance_software- Published: Jun. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-19148
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for ... Read more
Affected Products : caddy- Published: Nov. 10, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3134
Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : businessobjects- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3849
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser paramet... Read more
Affected Products : imember360- Published: May. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2715
Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugins for Drupal 7.x allow remote attackers to inject arbitrary web script or HTML via the (1) module or (2) message parameter to index.ph... Read more
Affected Products : videowhisper- Published: Apr. 28, 2014
- Modified: Apr. 12, 2025