Latest CVE Feed
-
4.3
MEDIUMCVE-2022-0406
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.... Read more
- EPSS Score: %0.13
- Published: Apr. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-44436
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT... Read more
- EPSS Score: %0.19
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22349
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Fo... Read more
Affected Products : sterling_external_authentication_server- EPSS Score: %0.38
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43792
Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature. A tag group may only allow a certain group (e.g. staff) to view certain ... Read more
Affected Products : discourse- EPSS Score: %0.28
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20620
Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : ssh_agent- EPSS Score: %0.97
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21692
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat ... Read more
Affected Products : onionshare- EPSS Score: %0.15
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20614
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.... Read more
- EPSS Score: %2.21
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43538
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird... Read more
- EPSS Score: %0.23
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20618
A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : bitbucket_branch_source- EPSS Score: %1.14
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0616
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack... Read more
Affected Products : amelia- EPSS Score: %0.10
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1956
The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them.... Read more
Affected Products : shortcut_macros- EPSS Score: %0.08
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20613
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.... Read more
- EPSS Score: %0.09
- Published: Jan. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22243
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabiliti... Read more
Affected Products : junos- EPSS Score: %0.42
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1545
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.... Read more
Affected Products : gitlab- EPSS Score: %0.35
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1004
Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.... Read more
Affected Products : otrs- EPSS Score: %0.23
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1124
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled... Read more
Affected Products : gitlab- EPSS Score: %0.24
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1914
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and esc... Read more
Affected Products : clean-contact- EPSS Score: %0.10
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43531
When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violat... Read more
Affected Products : firefox- EPSS Score: %0.14
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43533
When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.... Read more
Affected Products : firefox- EPSS Score: %0.28
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1092
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog... Read more
Affected Products : mycred- EPSS Score: %0.10
- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024