Latest CVE Feed
-
4.3
MEDIUMCVE-2023-4943
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscri... Read more
Affected Products : bear_-_woocommerce_bulk_editor_and_products_manager_professional- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-36750
The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauth... Read more
Affected Products : image_optimizer- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4940
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attack... Read more
Affected Products : bear_-_woocommerce_bulk_editor_and_products_manager_professional- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1124
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it ... Read more
Affected Products : eventprime- Published: Mar. 09, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2023-2020
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.... Read more
- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-0385
The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for unauthe... Read more
- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-10299
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access v... Read more
Affected Products : agile_product_lifecycle_management_framework agile_plm agile_product_lifecycle_management- Published: Oct. 19, 2017
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2021-4427
The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wor... Read more
Affected Products : vuukle_comments\,_reactions\,_share_bar\,_revenue- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1705
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.... Read more
Affected Products : security_privileged_identity_manager- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4407
The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated... Read more
Affected Products : custom_banners- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4422
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthentica... Read more
- Published: Jul. 12, 2023
- Modified: Jun. 04, 2025
-
4.3
MEDIUMCVE-2017-1766
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.... Read more
Affected Products : business_process_manager- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3202
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to pu... Read more
Affected Products : mstore_api- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-22088
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: User Management). Supported versions that are affected are 7.4.0 and 7.4.1. Easily exploitable vulnerability allows low pri... Read more
Affected Products : communications_order_and_service_management- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0352
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for D... Read more
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0289
Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid... Read more
Affected Products : isync- Published: May. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-3867
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.... Read more
Affected Products : nomad- Published: Nov. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-6550
Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808.... Read more
Affected Products : zeroclipboard- Published: Apr. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6464
Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that overrides methods of unspecified native objects in documents that have different origins.... Read more
Affected Products : opera_browser- Published: Jan. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6137
rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensit... Read more
- Published: May. 21, 2013
- Modified: Apr. 11, 2025