Latest CVE Feed
-
4.3
MEDIUMCVE-2019-1003035
An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgentTemplate.java, src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with... Read more
Affected Products : azure_vm_agents- Published: Mar. 08, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-10018
Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Strategic Sourcing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
Affected Products : peoplesoft_enterprise_scm_strategic_sourcing- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2018-1000815
Brave Software Inc. Brave version version 0.22.810 to 0.24.0 contains a Other/Unknown vulnerability in function ContentSettingsObserver::AllowScript() in content_settings_observer.cc that can result in Websites can run inline JavaScript even if script is ... Read more
Affected Products : brave- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1513
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tic... Read more
Affected Products : resin- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-0205
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allo... Read more
Affected Products : ubuntu_linux fedora debian_linux libpng mac_os_x opensuse linux_enterprise_server- Published: Mar. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-35300
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.... Read more
Affected Products : zammad- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-19413
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access c... Read more
Affected Products : sonarqube- Published: Dec. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-37855
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser. ... Read more
Affected Products : wp_6070-wvps_firmware wp_6101-wxps_firmware wp_6121-wxps_firmware wp_6156-whps_firmware wp_6185-whps_firmware wp_6215-whps_firmware wp_6070-wvps wp_6101-wxps wp_6121-wxps wp_6156-whps +2 more products- Published: Aug. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0222
IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.... Read more
- Published: Mar. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-39553
Missing Authorization vulnerability in andy_moyle Church Admin. This issue affects Church Admin: from n/a through 5.0.9.... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2006-2755
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.... Read more
Affected Products : ubb.threads- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-24570
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin ... Read more
Affected Products : accept_donations_with_paypal- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34750
A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege c... Read more
- Published: Nov. 15, 2024
- Modified: Aug. 06, 2025
-
4.3
MEDIUMCVE-2013-7397
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting ... Read more
- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3654
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomS... Read more
- Published: Nov. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-42923
Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and avail... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2020-3888
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously crafted page may interfere with other web contexts.... Read more
- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3645
Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : orchard- Published: Jun. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-30965
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-6574
Cross-site scripting (XSS) vulnerability in the Fonecta verify module 7.x-1.x before 7.x-1.6 for Drupal allows remote attackers from certain sources to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 27, 2013
- Modified: Apr. 11, 2025