Latest CVE Feed
-
4.0
MEDIUMCVE-2006-7242
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-001 does not ensure that the AE Administrator role is present for Site Preferences modifications, which allows remote authenticated users to bypass intended ac... Read more
Affected Products : filenet_p8_application_engine- EPSS Score: %0.12
- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-2584
Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerabili... Read more
Affected Products : hyperion- EPSS Score: %0.15
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-3505
The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration file.... Read more
Affected Products : groundwork_monitor- EPSS Score: %0.31
- Published: May. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0470
HTTPD in IBM Netezza Performance Portal 1.0.2 allows remote authenticated users to list application directories containing asset files via a direct request to a directory URI, as demonstrated by listing image files.... Read more
- EPSS Score: %0.16
- Published: Apr. 05, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-1551
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.25
- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2016-5979
IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM ... Read more
Affected Products : distributed_marketing- EPSS Score: %0.24
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2023-23469
IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force... Read more
Affected Products : cloud_pak_for_business_automation- EPSS Score: %0.03
- Published: Feb. 01, 2023
- Modified: Mar. 26, 2025
-
4.0
MEDIUMCVE-2015-2139
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5... Read more
- EPSS Score: %0.21
- Published: Aug. 27, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3646
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone ... Read more
- EPSS Score: %0.15
- Published: May. 12, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2008-5742
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url ... Read more
Affected Products : netcat- EPSS Score: %1.16
- Published: Dec. 26, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2020-2581
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: LLVM Interpreter). The supported version that is affected is 19.3.0.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastr... Read more
Affected Products : graalvm- EPSS Score: %0.71
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2016-8579
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.... Read more
Affected Products : docker2aci- EPSS Score: %0.13
- Published: Oct. 28, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2006-0616
Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."... Read more
- EPSS Score: %3.72
- Published: Feb. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2017-10317
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with logon... Read more
Affected Products : hospitality_suite8- EPSS Score: %0.18
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2025-54142
Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin serv... Read more
Affected Products : akamaighost- Published: Aug. 29, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2015-0299
Multiple cross-site scripting (XSS) vulnerabilities in Open Source Point of Sale 2.3.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : open_source_point_of_sale- EPSS Score: %0.16
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2020-6306
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).... Read more
Affected Products : leasing- EPSS Score: %0.23
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-26417
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges ... Read more
Affected Products : android- Published: Aug. 26, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2025-22413
In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation... Read more
Affected Products : android- Published: Aug. 26, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2008-4500
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".... Read more
- EPSS Score: %8.69
- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025