Latest CVE Feed
-
4.0
MEDIUMCVE-2006-4418
Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file.... Read more
Affected Products : wikepage- EPSS Score: %12.41
- Published: Aug. 28, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2013-1814
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password f... Read more
Affected Products : rave- EPSS Score: %87.05
- Published: Mar. 14, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2019-16181
In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.... Read more
Affected Products : limesurvey- EPSS Score: %0.24
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2013-4192
sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to spoof emails via unspecified vectors.... Read more
Affected Products : plone- EPSS Score: %0.22
- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3945
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to ... Read more
Affected Products : typo3- EPSS Score: %0.20
- Published: Jun. 03, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2118
Unspecified vulnerability in the Secure Pull Print and Security Pull Print components in HP Access Control (AC) Software 12.x through 14.x before 14.1.2 allows remote authenticated users to obtain sensitive information via unknown vectors.... Read more
Affected Products : access_control- EPSS Score: %0.20
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3303
The web framework in Cisco WebEx Meetings Server does not properly restrict the content of query strings, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser ... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.38
- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3087
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity refere... Read more
- EPSS Score: %0.29
- Published: Aug. 17, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0760
The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.... Read more
Affected Products : adaptive_security_appliance_software- EPSS Score: %0.30
- Published: Jun. 04, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-19421
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.... Read more
- EPSS Score: %0.22
- Published: Nov. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-3379
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified... Read more
Affected Products : views- EPSS Score: %0.25
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3332
Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authenticated users to establish undetected concurrent logins via unspecified vectors, aka Bug ID CSCup98029.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.35
- Published: Aug. 11, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-2597
Multiple directory traversal vulnerabilities in Siemens WinCC 7.0 SP3 before Update 2 allow remote authenticated users to read arbitrary files via a crafted parameter in a URL.... Read more
Affected Products : wincc- EPSS Score: %0.18
- Published: Jun. 08, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-1993
The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.21
- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-3507
The NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to obtain sensitive information via a direct request for (1) a configuration file, (2) a database dump, or (3) the Tomcat status context.... Read more
Affected Products : groundwork_monitor- EPSS Score: %0.32
- Published: May. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-4502
The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.... Read more
- EPSS Score: %0.17
- Published: May. 13, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-5336
lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.... Read more
- EPSS Score: %0.16
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-0702
Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified vectors.... Read more
- EPSS Score: %0.15
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-4195
Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.... Read more
Affected Products : ios_xr- EPSS Score: %0.60
- Published: Jun. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4219
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive informat... Read more
- EPSS Score: %0.41
- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025