Latest CVE Feed
-
4.0
MEDIUMCVE-2024-21100
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : commerce_platform- Published: Apr. 16, 2024
- Modified: Dec. 06, 2024
-
4.0
MEDIUMCVE-2020-36826
A vulnerability was found in AwesomestCode LiveBot. It has been classified as problematic. Affected is the function parseSend of the file js/parseMessage.js. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Thi... Read more
Affected Products :- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-10132
A vulnerability classified as problematic was found in Thimo Grauerholz WP-Spreadplugin up to 3.8.6.1 on WordPress. This vulnerability affects unknown code of the file spreadplugin.php. The manipulation of the argument Spreadplugin leads to cross site scr... Read more
Affected Products :- Published: Apr. 21, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-25101
A vulnerability, which was classified as problematic, has been found in l2c2technologies Koha up to 20180108. This issue affects some unknown processing of the file /cgi-bin/koha/opac-MARCdetail.pl. The manipulation of the argument biblionumber with the i... Read more
Affected Products :- Published: Apr. 22, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-4906
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.... Read more
- EPSS Score: %0.05
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-21260
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.... Read more
Affected Products : mattermost_server- EPSS Score: %0.23
- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-4650
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.... Read more
Affected Products : maximo_spatial_asset_management- EPSS Score: %0.04
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-24403
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorize... Read more
- EPSS Score: %0.27
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-4344
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.... Read more
Affected Products : tivoli_business_service_manager- EPSS Score: %0.05
- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2016-11077
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.... Read more
Affected Products : mattermost_server- EPSS Score: %0.18
- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-4846
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.22
- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-14341
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installat... Read more
Affected Products : single_sign-on- EPSS Score: %0.30
- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-11352
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the config... Read more
Affected Products : wallabag- EPSS Score: %0.45
- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-2467
BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 displays the internal IP address of the WebLogic server in the WebLogic Server Administration Console, which allows remote authenticated administrators to determine the address.... Read more
Affected Products : weblogic_server- EPSS Score: %0.32
- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2016-0234
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.03
- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-1466
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.... Read more
- EPSS Score: %0.68
- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2023-21428
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.... Read more
- EPSS Score: %0.03
- Published: Feb. 09, 2023
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-0863
The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified ... Read more
Affected Products : cognos_tm1- EPSS Score: %0.20
- Published: Sep. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2009-3100
xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking t... Read more
- EPSS Score: %0.04
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-0920
IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : spss_analytic_server- EPSS Score: %0.18
- Published: Apr. 10, 2014
- Modified: Apr. 12, 2025