Latest CVE Feed
-
4.0
MEDIUMCVE-2013-4832
HP Service Manager 9.30 through 9.32 allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : service_manager- EPSS Score: %0.21
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4487
The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created.... Read more
- EPSS Score: %0.16
- Published: Nov. 02, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-6486
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Talent Acquisition Manager - Security.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.19
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-1450
Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive ... Read more
Affected Products : internet_explorer- EPSS Score: %16.55
- Published: Jan. 29, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0672
The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings via a request to this interface.... Read more
Affected Products : mediasense- EPSS Score: %0.50
- Published: Jan. 22, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2018-1962
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID... Read more
Affected Products : security_identity_manager- EPSS Score: %0.05
- Published: Feb. 04, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-5544
The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.... Read more
- EPSS Score: %0.20
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-3029
The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : advanced_threat_defense- EPSS Score: %0.16
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6371
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path... Read more
Affected Products : thecartpress_ecommerce_shopping_cart- EPSS Score: %14.40
- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3379
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified... Read more
Affected Products : views- EPSS Score: %0.25
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-6687
The web portal in the Enterprise License Manager component in Cisco WebEx Meetings Server allows remote authenticated users to discover the cleartext administrative password by reading HTML source code, aka Bug ID CSCul33876.... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.16
- Published: Jan. 16, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-4874
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.... Read more
Affected Products : track-it\!- EPSS Score: %16.06
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2071
Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filepath parameter.... Read more
Affected Products : samepage- EPSS Score: %14.95
- Published: Feb. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-4044
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.... Read more
Affected Products : spss_collaboration_and_deployment_services- EPSS Score: %0.18
- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-4195
Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.... Read more
Affected Products : ios_xr- EPSS Score: %0.60
- Published: Jun. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-8887
IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to upload arbitrary GIFAR files, and consequently modify data, via un... Read more
Affected Products : marketing_operations- EPSS Score: %0.20
- Published: Jun. 07, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6222
Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to read arbitrary files via a ..... Read more
Affected Products : marketing_operations- EPSS Score: %0.40
- Published: Jun. 07, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-8079
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to header background setting.... Read more
- EPSS Score: %0.34
- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-5534
Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, vi... Read more
Affected Products : unity_connection- EPSS Score: %0.26
- Published: Oct. 19, 2013
- Modified: Apr. 11, 2025