Latest CVE Feed
-
4.3
MEDIUMCVE-2019-4222
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231.... Read more
Affected Products : sterling_b2b_integrator- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3317
Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.... Read more
- Published: May. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-5942
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.... Read more
Affected Products : garoon- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4015
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.... Read more
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0463
Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties.... Read more
Affected Products : workflow- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-34809
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1414
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours... Read more
- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2020-4548
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Conte... Read more
- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3664
The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the set_thumbnail and delete_thumbnail functions in all versions up to, and including, 13.7.0. This makes it possible fo... Read more
Affected Products :- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1543
Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site.... Read more
- Published: Apr. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-37532
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.... Read more
Affected Products : business_one- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43961
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.... Read more
Affected Products : nexus_repository_manager- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22868
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read f... Read more
Affected Products : enterprise_server- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-7098
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3) the gallery, possibly the Description field in Your Pic... Read more
Affected Products : k-rate- Published: Aug. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-28644
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.... Read more
Affected Products : owncloud- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-31818
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access... Read more
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4846
Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.... Read more
Affected Products : metaslider- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-46599
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1935
Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.... Read more
Affected Products : campus_pipeline- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-42069
When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024