Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2727
The (1) templatewrap/templatefoot.php, (2) cmsjs/plugin.js.php, and (3) cmsincludes/cms_plugin_api_link.inc.php scripts in Tribal Tribiq CMS before 5.2.7c allow remote attackers to obtain sensitive information via a direct request, which reveals the full ... Read more
Affected Products : tribiq_cms- Published: Dec. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-4841
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to IND... Read more
- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3894
Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header.... Read more
Affected Products : multifunctional_mailform_free- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-100027
Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : wp_slimstat- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8037
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory.... Read more
Affected Products : fortimanager_firmware- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3892
Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : meridian- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-31472
Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the data of Cabinet.... Read more
Affected Products : garoon- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1254
Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : segue- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-40198
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.... Read more
Affected Products : terawallet- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-51523
Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.... Read more
Affected Products :- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-14519
An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.... Read more
Affected Products : kirby- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8422
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, cred... Read more
Affected Products : manageengine_remote_access_plus- Published: Jan. 31, 2020
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2022-36800
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected version... Read more
Affected Products : jira_service_management- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0984
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain pas... Read more
- Published: Apr. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-7258
Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "displaying group DN and entry data in group administration UI."... Read more
Affected Products : web2ldap- Published: Jan. 03, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13718
The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on several func... Read more
Affected Products : flexible_wishlist_for_woocommerce- Published: Feb. 18, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-11709
The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ai_post_generator_delete_Post AJAX action in all versions up to, and including, 3.5. This makes it possible... Read more
Affected Products : ai_post_generator_\|_autowriter- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2023-23823
Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8.... Read more
Affected Products : enhanced_text_widget- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2024-43229
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Search Analytics: from n/a through 1.4.9.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2021-1143
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET reques... Read more
Affected Products : connected_mobile_experiences- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024