Latest CVE Feed
-
4.3
MEDIUMCVE-2009-1080
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.... Read more
Affected Products : java_system_identity_manager- Published: Mar. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-4917
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Jul. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3336
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack... Read more
Affected Products : event_monster- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-3331
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object refe... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
4.3
MEDIUMCVE-2022-4376
An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a Gi... Read more
Affected Products : gitlab- Published: May. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1290
ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.... Read more
- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-43753
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.... Read more
- Published: Nov. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-2450
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.... Read more
Affected Products : resmush.it_image_optimizer- Published: Nov. 14, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-46807
Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.... Read more
Affected Products : stock_sync_for_woocommerce- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2022-3447
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1955
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php and (2) datePicker.php in Easy PHP Calendar 6.x and 7.x before 7.0.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : easy_php_calendar- Published: Jul. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-41944
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sens... Read more
Affected Products : discourse- Published: Nov. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1728
The IonMonkey JavaScript engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21, when Valgrind mode is used, does not properly initialize memory, which makes it easier for remote attackers to obtain sensitive information... Read more
- Published: Sep. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-46685
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.... Read more
Affected Products : gitea- Published: Dec. 12, 2022
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2022-47148
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.... Read more
Affected Products : woocommerce_pdf_invoices\&_packing_slips- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-46725
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.... Read more
- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-43857
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log file... Read more
- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-41251
A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : apprenda- Published: Sep. 21, 2022
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2022-41708
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.... Read more
Affected Products : messenger- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2022-41263
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise re... Read more
Affected Products : business_objects_business_intelligence_platform- Published: Dec. 12, 2022
- Modified: Nov. 21, 2024