Latest CVE Feed
-
4.0
MEDIUMCVE-2015-1608
Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vec... Read more
Affected Products : opportunity_form- EPSS Score: %0.40
- Published: Feb. 16, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-10521
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.28
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-19420
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upl... Read more
- EPSS Score: %0.22
- Published: Nov. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-0994
Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.... Read more
Affected Products : ignition- EPSS Score: %0.25
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2009-2125
delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs.... Read more
Affected Products : elvinbts- EPSS Score: %0.15
- Published: Jun. 19, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-1264
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.... Read more
- EPSS Score: %0.36
- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-4511
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage... Read more
Affected Products : tandberg_video_communication_server- EPSS Score: %1.71
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-1982
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more
Affected Products : infosphere_master_data_management- EPSS Score: %0.16
- Published: Jul. 20, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-2446
Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via vectors related to QAS.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.17
- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2019-13922
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker wi... Read more
Affected Products : sinema_remote_connect_server- EPSS Score: %0.10
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2009-5072
Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.... Read more
Affected Products : tivoli_directory_server- EPSS Score: %0.36
- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2021-40087
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be ... Read more
Affected Products : ejbca- EPSS Score: %0.10
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2011-4581
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.... Read more
Affected Products : moodle- EPSS Score: %0.20
- Published: Jul. 20, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2018-2916
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks). The supported version that is affected is Prior to 8.7.18. Easily exploitable vulnerability allows high privileged attac... Read more
- EPSS Score: %0.45
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4112
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.05
- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-14023
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.... Read more
- EPSS Score: %0.07
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2011-4679
vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.... Read more
Affected Products : vtiger_crm- EPSS Score: %0.16
- Published: Dec. 07, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2022-39914
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.... Read more
- EPSS Score: %0.02
- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2010-4754
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions ... Read more
- EPSS Score: %1.83
- Published: Mar. 02, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-0154
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot... Read more
- EPSS Score: %0.13
- Published: Sep. 14, 2010
- Modified: Apr. 11, 2025