Latest CVE Feed
-
4.3
MEDIUMCVE-2021-31446
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malici... Read more
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-7417
Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery... Read more
Affected Products : ipcop- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-32170
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.... Read more
Affected Products : bytebase- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2024-11911
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authe... Read more
Affected Products : wp_crowdfunding- Published: Dec. 13, 2024
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2024-43157
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.... Read more
Affected Products : formcraft- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-42164
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
4.3
MEDIUMCVE-2010-2150
Cross-site scripting (XSS) vulnerability Fujitsu e-Pares V01 L01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : e-pares- Published: Jun. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-6349
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1087
The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack... Read more
Affected Products : wc_sales_notification- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
4.3
MEDIUMCVE-2012-1209
Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.... Read more
Affected Products : fork_cms- Published: Feb. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-32434
Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce.This issue affects Order Delivery Date for WooCommerce: from n/a through 3.20.2. ... Read more
Affected Products : order_delivery_date_for_woocommerce- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1046
Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.... Read more
Affected Products : cognos_tm1- Published: Feb. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-0761
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack... Read more
Affected Products : clock_in_portal-_staff_\&_attendance_management- Published: May. 15, 2023
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2024-43319
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.... Read more
Affected Products : html5_video_player- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.3
MEDIUMCVE-2024-1906
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxAddCategory function. This makes it possible for unaut... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2024-43265
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2024-3825
Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1952
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels ... Read more
- Published: Feb. 29, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2025-23188
An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on conf... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-32162
CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.... Read more
Affected Products : cmseasy- Published: Apr. 17, 2024
- Modified: Apr. 14, 2025