Latest CVE Feed
-
4.3
MEDIUMCVE-2024-11355
The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for a... Read more
Affected Products : ultimate_youtube_video_\&_shorts_player_with_vimeo- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
4.3
MEDIUMCVE-2021-36865
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.... Read more
- Published: Sep. 30, 2022
- Modified: Feb. 20, 2025
-
4.3
MEDIUMCVE-2021-34916
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8675
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and including, 2.1.2. This makes it possible for authenticated a... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2025-53341
Missing Authorization vulnerability in Themovation Stratus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Stratus: from n/a through 4.2.5.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-54269
Missing Authorization vulnerability in Ninja Team Notibar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notibar: from n/a through 2.1.4.... Read more
Affected Products :- Published: Dec. 11, 2024
- Modified: Dec. 11, 2024
-
4.3
MEDIUMCVE-2021-34901
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-48290
An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2022-27575
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34890
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-47850
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning... Read more
Affected Products : youtrack- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2006-2886
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another v... Read more
Affected Products : knowledgetree_open_source- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-51460
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.... Read more
Affected Products : infosphere_information_server- Published: Dec. 11, 2024
- Modified: Jan. 14, 2025
-
4.3
MEDIUMCVE-2024-42504
A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2022-22329
IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be... Read more
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-24446
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.... Read more
Affected Products : manageengine_key_manager_plus- Published: Mar. 01, 2022
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2024-48047
Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce allows Cross Site Request Forgery.This issue affects Linked Variation for WooCommerce: from n/a through 1.0.5.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
4.3
MEDIUMCVE-2023-6243
The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email function. ... Read more
Affected Products : eventon-lite- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-10664
The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the basepress_db_posts_update() function in all versions up to, and including, 2.1... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
4.3
MEDIUMCVE-2023-49758
Missing Authorization vulnerability in Veribo, Roland Murg WP Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Booking System: from n/a through 2.0.19.2.... Read more
Affected Products : wp_booking_system- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024