Latest CVE Feed
-
4.0
MEDIUMCVE-2024-52614
Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If this vulnerability is exploited, a local attacker may obtain the login ID and password for the affected product.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2013-3425
The Meeting Center component in Cisco WebEx 11 generates different error messages for invalid file-access attempts depending on whether a file exists, which allows remote authenticated users to enumerate files via a series of SPI calls, aka Bug ID CSCuc35... Read more
Affected Products : webex- EPSS Score: %0.18
- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-2346
XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated users to read arbitrary files via the req parameter.... Read more
Affected Products : seq_analyst- EPSS Score: %0.12
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3350
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCuh84870.... Read more
Affected Products : cloud_portal- EPSS Score: %0.27
- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3400
Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive information by reading logs, aka Bug IDs CSCuq36417 and CSCuq40344.... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.16
- Published: Oct. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-4432
Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed ... Read more
Affected Products : mahara- EPSS Score: %0.19
- Published: May. 19, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3282
The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive number-translation informa... Read more
Affected Products : unified_communications_domain_manager- EPSS Score: %0.39
- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-3154
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1.0 allows remote authenticated users to affect confidentiality, related to ATTACH.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.19
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-4800
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.... Read more
Affected Products : multi_server- EPSS Score: %1.46
- Published: Apr. 22, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2007-3604
vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.... Read more
Affected Products : vtiger_crm- EPSS Score: %0.22
- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2012-4495
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.... Read more
- EPSS Score: %0.36
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-2011
Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain sensitive information by decrypting a field's contents.... Read more
Affected Products : dynamics_gp- EPSS Score: %25.14
- Published: May. 21, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-30124
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.... Read more
Affected Products : sametime- Published: Oct. 23, 2024
- Modified: Oct. 29, 2024
-
4.0
MEDIUMCVE-2014-9155
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploade... Read more
Affected Products : avatar_uploader- EPSS Score: %1.25
- Published: Dec. 01, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2990
Directory traversal vulnerability in zhtml.cgi in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticated users to read arbitrary files via a crafted parameter.... Read more
Affected Products : desknet_neo- EPSS Score: %0.48
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2007-3839
Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 010306 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the avatar parameter. NOTE: this may be related to the tracker program... Read more
Affected Products : dr- EPSS Score: %0.28
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-4545
Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory.... Read more
Affected Products : unity- EPSS Score: %0.28
- Published: Oct. 13, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2013-4038
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent att... Read more
- EPSS Score: %0.21
- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0830
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathnam... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.24
- Published: Feb. 01, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-1948
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses ... Read more
Affected Products : lotus_notes- EPSS Score: %0.30
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025