Latest CVE Feed
-
4.3
MEDIUMCVE-2013-5780
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confident... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-33593
Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91. ... Read more
Affected Products : smart_forms- Published: Apr. 29, 2024
- Modified: Apr. 08, 2025
-
4.3
MEDIUMCVE-2013-6015
Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of... Read more
- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6336
The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (ap... Read more
Affected Products : wireshark- Published: Nov. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-2119
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE messag... Read more
- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-1595
The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP address mappings, which allows man-in-the-middle attackers to discover alarm IP addresses and spoof servers by intercepting the client-server... Read more
Affected Products : spcanywhere- Published: Mar. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6790
The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web ... Read more
Affected Products : chrome- Published: Dec. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1582
Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the appid parameter in a registration task to the default URI or remote adm... Read more
Affected Products : spider_facebook- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-33585
Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This issue affects Payment Gateway Based Fees and Discounts for WooCommerce: from n/a through 2.12.1. ... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-2165
Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.... Read more
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-9219
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).... Read more
Affected Products : gitlab- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-7043
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7042.... Read more
- Published: Dec. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7032
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.... Read more
- Published: Oct. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9508
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs ... Read more
Affected Products : typo3- Published: Jan. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1570
The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.... Read more
Affected Products : forticlient- Published: Feb. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-9710
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1404
Cross-site scripting (XSS) vulnerability in the Content Rating Extbase extension 2.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : content_rating_extbase- Published: Feb. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1646
Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."... Read more
Affected Products : xml_core_services- Published: Apr. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1571
The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveragin... Read more
Affected Products : fortios- Published: Feb. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1567
Cross-site scripting (XSS) vulnerability in the admin page in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote authenticated users with the "edit gd infinite scroll settings" permission to inject arbitrary web script or HTML via unspe... Read more
Affected Products : gd_infinite_scroll- Published: Feb. 09, 2015
- Modified: Apr. 12, 2025