Latest CVE Feed
-
4.0
MEDIUMCVE-2016-0382
The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID: 112356.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2017-1783
IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.... Read more
- Published: Jan. 29, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-8007
Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019.... Read more
Affected Products : prime_infrastructure- Published: Dec. 20, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-4273
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to different res... Read more
Affected Products : entity_api- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-4020
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.... Read more
Affected Products : maximo_asset_management- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-4061
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors.... Read more
Affected Products : rational_policy_tester- Published: Sep. 09, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-3921
The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node privileges in certain circumstances involving subqueue creation, which allows remote authenticated users to discover arbitrary organic ... Read more
- Published: Nov. 09, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2015-3646
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone ... Read more
- Published: May. 12, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2023-23469
IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force... Read more
Affected Products : cloud_pak_for_business_automation- Published: Feb. 01, 2023
- Modified: Mar. 26, 2025
-
4.0
MEDIUMCVE-2013-2985
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013... Read more
- Published: Jul. 03, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2017-18466
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2011-4305
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.... Read more
Affected Products : moodle- Published: Jul. 11, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-2011
Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain sensitive information by decrypting a field's contents.... Read more
Affected Products : dynamics_gp- Published: May. 21, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-1298
Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal sequences in the f parameter. NOTE: the provenance of this information is unknown; the details are obtained solely fr... Read more
Affected Products : pulse_cms- Published: Apr. 06, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4583
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.... Read more
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-4835
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.... Read more
Affected Products : aims- Published: Sep. 14, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2021-21296
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live quer... Read more
Affected Products : fleet- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-2628
Unspecified vulnerability in HP Enterprise Maps 1 allows remote authenticated users to obtain sensitive information via unknown vectors.... Read more
Affected Products : enterprise_maps- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-1829
calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student... Read more
Affected Products : moodle- Published: Mar. 25, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-3514
Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect integrity, related to Enterprise Infrastructure SEC (JDENET).... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025