Latest CVE Feed
-
4.3
MEDIUMCVE-2013-7076
Cross-site scripting (XSS) vulnerability in Extension Manager in TYPO3 4.5.x before 4.5.32 and 4.7.x before 4.7.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : typo3- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7041
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.... Read more
Affected Products : pam_userdb- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-7040
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers t... Read more
- Published: May. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-0590
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-31341
Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).... Read more
Affected Products : database_replication- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4317
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal c... Read more
Affected Products : postgresql- Published: May. 14, 2024
- Modified: Mar. 28, 2025
-
4.3
MEDIUMCVE-2021-30804
A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malicious application may be able to access Find My data.... Read more
Affected Products : iphone_os- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-14595
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.... Read more
Affected Products : joomla\!- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-6491
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: Feb. 02, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-0660
Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create arbitrary files via specially crafted ATC file.... Read more
Affected Products : attachecase- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4463
The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4.7. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possib... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-27264
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a ma... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-27595
When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-19494
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.... Read more
Affected Products : gitlab- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6170
Juniper Junos 10.0 before 10.0S28, 10.4 before 10.4R7, 11.1 before 11.1R5, 11.2 before 11.2R2, and 11.4 before 11.4R1, when in a Next-Generation Multicast VPN (NGEN MVPN) environment, allows remote attackers to cause a denial of service (RPD routing daemo... Read more
- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-54298
Missing Authorization vulnerability in Bill Minozzi Car Dealer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Dealer: from n/a through 4.46.... Read more
Affected Products : car_dealer- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2018-8545
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge.... Read more
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-27266
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a ma... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4767
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and ... Read more
- Published: May. 14, 2024
- Modified: Apr. 01, 2025
-
4.3
MEDIUMCVE-2016-5702
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.... Read more
Affected Products : phpmyadmin- Published: Jul. 03, 2016
- Modified: Apr. 12, 2025