Latest CVE Feed
-
4.0
MEDIUMCVE-2015-1480
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash... Read more
- EPSS Score: %18.23
- Published: Feb. 04, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2022-29253
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and ... Read more
Affected Products : xwiki- EPSS Score: %0.06
- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2022-33696
Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.... Read more
- EPSS Score: %0.02
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-44840
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By using the /core/table/query endpoint, and by using a POST request and indi... Read more
Affected Products : delta_rm- EPSS Score: %0.19
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-19420
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upl... Read more
- EPSS Score: %0.22
- Published: Nov. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2013-3428
The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that triggers an error, aka Bug ID CSCue65... Read more
Affected Products : secure_access_control_system- EPSS Score: %0.16
- Published: Jul. 15, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2016-3021
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.... Read more
- EPSS Score: %0.07
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2013-0679
Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving a query for a pathname.... Read more
- EPSS Score: %0.33
- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2022-1688
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections... Read more
Affected Products : note_press- EPSS Score: %0.17
- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2009-1264
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.... Read more
- EPSS Score: %0.36
- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-0724
The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.28
- Published: Feb. 13, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3959
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated user... Read more
- EPSS Score: %0.16
- Published: Jun. 14, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0656
Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface data via crafted field values, aka Bug ID CSCuj45353.... Read more
Affected Products : context_directory_agent- EPSS Score: %0.38
- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-4511
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage... Read more
Affected Products : tandberg_video_communication_server- EPSS Score: %1.71
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0640
EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to bypass intended restrictions on resource access via unspecified vectors.... Read more
Affected Products : rsa_archer_egrc- EPSS Score: %0.20
- Published: Aug. 20, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2006-2468
The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain name in the Console login form, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : weblogic_server- EPSS Score: %0.32
- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2023-20838
In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418... Read more
- EPSS Score: %0.02
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-15136
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.... Read more
Affected Products : satellite- EPSS Score: %0.23
- Published: Feb. 27, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2022-39889
Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.... Read more
Affected Products : galaxywatch4plugin- EPSS Score: %0.10
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-20962
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization