Latest CVE Feed
-
4.0
MEDIUMCVE-2009-1017
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-0994.... Read more
Affected Products : application_server- EPSS Score: %2.57
- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-6542
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, C... Read more
Affected Products : database_server- EPSS Score: %0.17
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2011-4347
The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and ... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Jun. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2021-39901
In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.... Read more
Affected Products : gitlab- EPSS Score: %0.29
- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-5602
Multiple memory leaks in xsupplicant before 1.2.6, and possibly other versions, allow attackers to cause a denial of service (memory consumption) via unspecified vectors.... Read more
Affected Products : xsupplicant- EPSS Score: %0.71
- Published: Oct. 28, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-2185
The Call Detail Records (CDR) Management component in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCun74374.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.18
- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9154
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.... Read more
Affected Products : notify- EPSS Score: %0.18
- Published: Dec. 01, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-7195
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticate... Read more
- EPSS Score: %0.14
- Published: Nov. 21, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2007-5925
The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which t... Read more
Affected Products : mysql- EPSS Score: %12.13
- Published: Nov. 10, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2016-0369
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088.... Read more
Affected Products : forms_experience_builder- EPSS Score: %0.11
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-8735
The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords, which allows remote authenticated users with the "administer bad behavior" permission to obtain sensitive information by reading a log... Read more
Affected Products : bad_behavior- EPSS Score: %0.22
- Published: Nov. 12, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-2308
The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors.... Read more
Affected Products : online_service_gate- EPSS Score: %0.18
- Published: May. 09, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-1245
The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restri... Read more
Affected Products : webex_social- EPSS Score: %0.18
- Published: May. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-2102
Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575.... Read more
Affected Products : unified_contact_center_express_editor_software- EPSS Score: %0.18
- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2007-2557
MOStlyDB Admin in Mambo 4.6.1 does not properly check privileges, which allows remote authenticated administrators to have an unknown impact via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely fro... Read more
Affected Products : mambo- EPSS Score: %0.19
- Published: May. 09, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2020-8029
A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/sk... Read more
Affected Products : caas_platform- EPSS Score: %0.04
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-4990
The portal in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows local users to discover credentials by l... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.06
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2019-4635
IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.... Read more
Affected Products : security_secret_server- EPSS Score: %1.02
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2010-4439
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #14 and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality via unknown vectors related to eProfile - Manager D... Read more
Affected Products : peoplesoft_and_jdedwards_product_suite- EPSS Score: %0.38
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2022-27657
A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.... Read more
Affected Products : focused_run- EPSS Score: %0.29
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024