Latest CVE Feed
-
4.3
MEDIUMCVE-2024-44121
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not i... Read more
Affected Products :- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
4.3
MEDIUMCVE-2014-4571
Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter.... Read more
Affected Products : vn-calendar- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-9109
The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_oauth_data function in all versions up to, and including, 2.3.11. This make... Read more
Affected Products : woocommerce_ups_shipping- Published: Oct. 25, 2024
- Modified: Nov. 06, 2024
-
4.3
MEDIUMCVE-2025-52719
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss ProfileGrid allows Retrieve Embedded Sensitive Data. This issue affects ProfileGrid : from n/a through 5.9.5.2.... Read more
Affected Products : profilegrid- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-37883
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is reco... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3894
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete ... Read more
Affected Products : oauth_server- Published: Mar. 20, 2023
- Modified: Feb. 26, 2025
-
4.3
MEDIUMCVE-2009-3763
Unspecified vulnerability in the Access Manager / OpenSSO component in Oracle OpenSSO Enterprise 7.1, 7, 2005Q4, and 8.0 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : opensso_enterprise- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-30216
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affect... Read more
Affected Products :- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-24599
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."... Read more
Affected Products : ox_app_suite- Published: May. 29, 2023
- Modified: Jan. 14, 2025
-
4.3
MEDIUMCVE-2009-1047
Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vecto... Read more
- Published: Mar. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1426
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via... Read more
Affected Products : antivirus norman_antivirus_\&_antispyware rising_antivirus f-prot_antivirus command_antivirus quick_heal- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1456
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line... Read more
Affected Products : nod32_antivirus esafe norman_antivirus_\&_antispyware panda_antivirus rising_antivirus f-prot_antivirus endpoint_protection sophos_anti-virus comodo_antivirus anti-malware +10 more products- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-23981
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).... Read more
Affected Products : perfect_brands_for_woocommerce- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32516
Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5. ... Read more
Affected Products : multi_currency_for_woocommerce- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-29093
Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3. ... Read more
Affected Products :- Published: Mar. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1669
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.... Read more
Affected Products : phpmoneybooks- Published: Nov. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-3308
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.... Read more
- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-3200
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_message function. This makes it possible for unauthenticated attackers to update new order message via a forged ... Read more
Affected Products : mstore_api- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8071
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerP... Read more
Affected Products : openmrs- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2917
Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.... Read more
Affected Products : mpeg_encoder- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025