Latest CVE Feed
-
4.3
MEDIUMCVE-2021-4364
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authentica... Read more
Affected Products : jobsearch_wp_job_board- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6611
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-mi... Read more
- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-1251
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.... Read more
Affected Products : ask_me- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-0305
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or doma... Read more
Affected Products : netweaver_process_integration- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34371
Missing Authorization vulnerability in Hamid Alinia – idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.7.18. ... Read more
Affected Products : login_with_phone_number- Published: May. 06, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8071
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerP... Read more
Affected Products : openmrs- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-25930
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerab... Read more
- Published: May. 20, 2021
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2013-6037
Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.... Read more
Affected Products : secure_mail_gateway- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-52719
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss ProfileGrid allows Retrieve Embedded Sensitive Data. This issue affects ProfileGrid : from n/a through 5.9.5.2.... Read more
Affected Products : profilegrid- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-30865
Cross-Site Request Forgery (CSRF) vulnerability in fuzzoid 3DPrint Lite allows Cross Site Request Forgery. This issue affects 3DPrint Lite: from n/a through 2.1.3.5.... Read more
Affected Products : 3dprint_lite- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-12526
The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.0. This is due to missing or incorrect nonce validation on the 'albfre_user_action' AJAX action. T... Read more
Affected Products : arena.im- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2016-5945
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5507
Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : inline_entity_form- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-30926
Missing Authorization vulnerability in KingAddons.com King Addons for Elementor. This issue affects King Addons for Elementor: from n/a through 24.12.58.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2006-6882
Cross-site scripting (XSS) vulnerability in golden book allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : golden_book- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6645
Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of ... Read more
Affected Products : finder- Published: Apr. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-37511
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved. ... Read more
Affected Products : traveler_to_do- Published: Aug. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3763
Unspecified vulnerability in the Access Manager / OpenSSO component in Oracle OpenSSO Enterprise 7.1, 7, 2005Q4, and 8.0 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : opensso_enterprise- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12148
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.... Read more
Affected Products : devolutions_server- Published: Dec. 04, 2024
- Modified: Mar. 28, 2025
-
4.3
MEDIUMCVE-2022-27576
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024