Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13416
Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated version 2.46 of 2N OS, where this vulnerability is mitigated. It is recommended that all customers... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2023-28810
Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local netw... Read more
- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-36751
The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_meta() function. This makes it possible for unauthenticated attacke... Read more
Affected Products : coupon_creator- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-36753
The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers ... Read more
Affected Products : hueman- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-36758
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possibl... Read more
Affected Products : rss_aggregator_by_feedzy- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3849
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : pmwiki- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-29705
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.... Read more
Affected Products : code-gen- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-29288
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A privileged attacker could leverage this vulnerability... Read more
- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0472
Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.... Read more
Affected Products : burning_board- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-26903
Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery allows Cross Site Request Forgery. This issue affects InPost Gallery: from n/a through 2.1.4.3.... Read more
Affected Products : inpost_gallery- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2016-4841
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.... Read more
Affected Products : mailwise- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4868
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.... Read more
Affected Products : office- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4844
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.... Read more
Affected Products : mailwise- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2018-15432
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An att... Read more
Affected Products : prime_infrastructure- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-1942
Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : esis_enterprise_student_information_system- Published: Apr. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-0370
Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : cpanel- Published: Jan. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-1599
Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field.... Read more
Affected Products : subject_search_server- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5059
Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL allow remote attackers to inject arbitrary web script or HTML via several vectors, as demonstrated by the (1) uname and (2) pass parameters in a login form, and (3) an unspecified "url value,... Read more
Affected Products : greensql- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4975
Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.... Read more
Affected Products : b1gmail- Published: Sep. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4899
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.ph... Read more
Affected Products : boinc_forum- Published: Sep. 14, 2007
- Modified: Apr. 09, 2025