Latest CVE Feed
-
4.3
MEDIUMCVE-2022-0384
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43206
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username an... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0406
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.... Read more
- Published: Apr. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3457
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.... Read more
Affected Products : flash_player- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-43273
An Out-of-bounds Read vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.11. Crafted data in a DGN file and lack of verification of input data can trigger a read past the end of an allocated buffer. An ... Read more
Affected Products : drawings_sdk- Published: Nov. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3672
The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service (out-of-bounds array access and... Read more
Affected Products : ffmpeg- Published: Jun. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-0338
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3. ... Read more
Affected Products : loguru- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43293
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).... Read more
Affected Products : nexus_repository_manager- Published: Nov. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.... Read more
Affected Products : wordpress- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-0287
The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog... Read more
Affected Products : mycred- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1468
On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at least guest role privileges can cause processing delays to iControl REST requests via undisclosed requests. Note: Softw... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +1 more products- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43538
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43546
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43531
When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violat... Read more
Affected Products : firefox- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-40769
Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitati... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0488
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43533
When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.... Read more
Affected Products : firefox- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-2886
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via a .docx document with empty bullet styles for parent bullets.... Read more
Affected Products : lotus_symphony- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-7078
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). ... Read more
Affected Products : foreman- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43105
A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack.... Read more
Affected Products : dns_server- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024