Latest CVE Feed
-
4.3
MEDIUMCVE-2020-4446
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.... Read more
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-19411
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific... Read more
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-8925
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated use... Read more
Affected Products : manageengine_netflow_analyzer- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3821
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.... Read more
Affected Products : campaign_enterprise- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-11808
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretic... Read more
Affected Products : ratpack- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2186
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.... Read more
Affected Products : amazon_ec2- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2184
A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.... Read more
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6233
SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-12101
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.... Read more
Affected Products : xt-commerce- Published: Apr. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-18365
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.... Read more
Affected Products : teamcity- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9387
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.... Read more
Affected Products : mahara- Published: Apr. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.... Read more
Affected Products : yith_woocommerce_wishlist yith_woocommerce_compare yith_woocommerce_quick_view yith_woocommerce_zoom_magnifier yith_woocommerce_ajax_search yith_woocommerce_badge_management yith_woocommerce_brands_add-on yith_woocommerce_request_a_quote yith_woocommerce_social_login yith_woocommerce_order_tracking +28 more products- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30106
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.... Read more
Affected Products : connections- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-10312
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with... Read more
Affected Products : exclusive_addons_for_elementor- Published: Oct. 29, 2024
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2019-4286
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.... Read more
Affected Products : maximo_anywhere- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4601
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.... Read more
Affected Products : rational_quality_manager- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-16768
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some interna... Read more
Affected Products : sylius- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-9541
The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render function in includes/widgets/canvas-menu/canvas-menu.php. This makes it possible for authenticate... Read more
Affected Products : news_kit_elementor_addons- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
4.3
MEDIUMCVE-2019-13237
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/w... Read more
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9468
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.... Read more
Affected Products : piwigo- Published: Mar. 26, 2020
- Modified: Nov. 21, 2024