Latest CVE Feed
-
4.3
MEDIUMCVE-2016-8294
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-31608
Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.... Read more
Affected Products : enterprise_protection- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2020-4989
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707.... Read more
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-27839
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.... Read more
Affected Products : internet- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6434
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possibl... Read more
Affected Products : premium_addons_for_elementor- Published: Jul. 04, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-5511
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : webcenter_sites- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-0363
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, mana... Read more
Affected Products : mycred- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3173
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.... Read more
Affected Products : snipe-it- Published: Sep. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-39339
user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic ... Read more
- Published: Nov. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0240
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by le... Read more
Affected Products : security_guardium_database_activity_monitor- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-30725
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.... Read more
- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1606
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.... Read more
Affected Products : m-files_server- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3233
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.... Read more
Affected Products : rdiffweb- Published: Sep. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43955
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38905
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-32169
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.... Read more
Affected Products : bytebase- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2024-7422
The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to missing or incorrect nonce validation on the tml_admin_save_ms_settings() function. This makes it possible for ... Read more
Affected Products :- Published: Aug. 16, 2024
- Modified: Aug. 19, 2024
-
4.3
MEDIUMCVE-2017-6918
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.... Read more
Affected Products : bigtree_cms- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2022-3850
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack... Read more
Affected Products : find_and_replace_all- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
4.3
MEDIUMCVE-2022-30738
Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.... Read more
Affected Products : internet- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024