Latest CVE Feed
-
4.3
MEDIUMCVE-2024-37443
Missing Authorization vulnerability in Automattic WP Job Manager - Resume Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager - Resume Manager: from n/a through 2.1.0.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-38727
Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2021-34782
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improp... Read more
- Published: Oct. 06, 2021
- Modified: Jul. 23, 2025
-
4.3
MEDIUMCVE-2024-39639
Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress File Upload: from n/a through 4.24.7.... Read more
Affected Products : wordpress_file_upload- Published: Nov. 01, 2024
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-34000
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.... Read more
Affected Products : moodle- Published: May. 31, 2024
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2021-4015
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : firefly_iii- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-37204
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.... Read more
Affected Products : propertyhive- Published: Nov. 01, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2024-32783
Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0.... Read more
Affected Products :- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-29953
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded pa... Read more
- Published: Jun. 26, 2024
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2024-36118
MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond their authority. This issue has been addressed in version 2.10.15-lts. Users of... Read more
Affected Products : metersphere- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-39751
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID... Read more
Affected Products : infosphere_information_server- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
4.3
MEDIUMCVE-2024-6491
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authe... Read more
- Published: Jul. 20, 2024
- Modified: Feb. 04, 2025
-
4.2
MEDIUMCVE-2020-27413
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.... Read more
Affected Products : mahavitaran- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2023-20844
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Iss... Read more
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2025-25586
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.... Read more
Affected Products : yimioa- Published: Mar. 18, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2023-21462
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.... Read more
- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2025-21214
Windows BitLocker Information Disclosure Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Jan. 14, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2024-37386
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, ... Read more
Affected Products : stormshield_network_security- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2024-32963
Navidrome is an open source web-based music collection server and streamer. In affected versions of Navidrome are subject to a parameter tampering vulnerability where an attacker has the ability to manipulate parameter values in the HTTP requests. The att... Read more
Affected Products : navidrome- Published: May. 01, 2024
- Modified: Aug. 26, 2025
-
4.2
MEDIUMCVE-2018-8435
A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide a high-entropy source, aka "Windows Hyper-V Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.... Read more
- Published: Sep. 13, 2018
- Modified: Nov. 21, 2024