Latest CVE Feed
-
4.3
MEDIUMCVE-2015-4725
Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : audioshare- Published: Jun. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-11334
An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay. Physically... Read more
- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-25451
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-34626
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.... Read more
Affected Products : piwigo- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-6465
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.... Read more
Affected Products : mattermost_server- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-26925
Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.... Read more
Affected Products :- Published: Feb. 26, 2025
- Modified: Feb. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-30631
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.... Read more
- Published: Mar. 29, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2014-9430
Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via the COMMENT parameter in an Add action.... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-34809
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3830
Cross-site scripting (XSS) vulnerability in info.php in TomatoCart 1.1.8.6.1 allows remote attackers to inject arbitrary web script or HTML via the faqs_id parameter.... Read more
Affected Products : tomatocart- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-6599
The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.11. This makes it possible for authenticated att... Read more
Affected Products :- Published: Jul. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-0328
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Librar... Read more
Affected Products : wpcode- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
4.3
MEDIUMCVE-2023-47845
Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.... Read more
Affected Products : grab_\&_save- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-46150
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches, unauthorized users may learn of the existence of hidden tags and that they have been applie... Read more
Affected Products : discourse- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22702
PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.... Read more
Affected Products : partkeepr- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-30546
Cross-Site Request Forgery (CSRF) vulnerability in boroV Cackle allows Cross Site Request Forgery. This issue affects Cackle: from n/a through 4.33.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-2295
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.... Read more
Affected Products : rgboard- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1452
The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a CAB file with a modified reserved1 field. NO... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-36743
The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possib... Read more
Affected Products : product_catalog_simple- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5099
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.... Read more
Affected Products : phpb2b- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025