Latest CVE Feed
-
4.3
MEDIUMCVE-2024-20937
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions that are affected are Prior to 9.2.8.1. Easily exploitable vulnerability allows low privileged attacker with ... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Feb. 17, 2024
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2022-24896
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious use... Read more
Affected Products : tuleap- Published: Jun. 09, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-30740
Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.... Read more
Affected Products : internet- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-30725
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.... Read more
- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-30738
Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.... Read more
Affected Products : internet- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1906
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxAddCategory function. This makes it possible for unaut... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2024-31364
Cross-Site Request Forgery (CSRF) vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2. ... Read more
Affected Products :- Published: Apr. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2258
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".... Read more
Affected Products : garoon- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2024-3275
The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber acces... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6434
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possibl... Read more
Affected Products : premium_addons_for_elementor- Published: Jul. 04, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3107
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissions a... Read more
Affected Products : spectra- Published: May. 02, 2024
- Modified: Feb. 06, 2025
-
4.3
MEDIUMCVE-2024-32146
Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-35560
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.... Read more
- Published: May. 22, 2024
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-0208
IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors.... Read more
Affected Products : websphere_commerce- Published: Mar. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-28173
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed... Read more
Affected Products : teamcity- Published: Mar. 06, 2024
- Modified: Dec. 16, 2024
-
4.3
MEDIUMCVE-2016-2882
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to obtain sensitive information by reading HTTP responses.... Read more
Affected Products : tririga_application_platform- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-2304
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.... Read more
Affected Products : integraxor- Published: Apr. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-3663
The WP Scraper plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_scraper_multi_scrape_action() function in all versions up to, and including, 5.7. This makes it possible for authenticated attackers, with... Read more
Affected Products :- Published: May. 22, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1948
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by ... Read more
Affected Products : security_identity_governance_and_intelligence- Published: Feb. 21, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1415
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.9. This is due to missing or incorrect nonce validation on several functions. This make... Read more
Affected Products : contact_form_\&_lead_form_elementor_builder- Published: May. 02, 2024
- Modified: Nov. 21, 2024