Latest CVE Feed
-
4.0
MEDIUMCVE-2025-8285
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2014-7177
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.... Read more
Affected Products : tuleap- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2023-30711
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.... Read more
- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-20909
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.... Read more
Affected Products : android- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
-
4.0
MEDIUMCVE-2022-39898
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.... Read more
- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-6100
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess v... Read more
Affected Products : moodle- Published: Jan. 27, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2021-25472
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.... Read more
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-20402
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. I... Read more
Affected Products : security_verify_information_queue- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-5464
Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-34617
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 12, 2024
-
4.0
MEDIUMCVE-2024-23765
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsive after sending 85 requests to this port. The content an... Read more
Affected Products :- Published: Jun. 26, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-44840
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By using the /core/table/query endpoint, and by using a POST request and indi... Read more
Affected Products : delta_rm- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-20478
IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.... Read more
Affected Products : cloud_pak_system- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-34599
Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.... Read more
- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-0731
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.... Read more
Affected Products : business_connector- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0930
Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.... Read more
Affected Products : argosoft_mail_server- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2010-4685
Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCt... Read more
Affected Products : ios- Published: Jan. 07, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2004-2616
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.... Read more
Affected Products : activepost_standard- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2015-7234
The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology and OSF Import modules are enabled, allows user-assisted remote attackers to delete arbitrary files via unspecified vectors.... Read more
Affected Products : open_semantic_framework- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-1568
IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.... Read more
- Published: Dec. 05, 2018
- Modified: Nov. 21, 2024