Latest CVE Feed
-
4.3
MEDIUMCVE-2020-29447
Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and fro... Read more
Affected Products : crucible- Published: Dec. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3832
Cross-site scripting (XSS) vulnerability in the Documents component in ownCloud Server 6.0.x before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.... Read more
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-16698
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a new... Read more
Affected Products : direct_mail- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-34115
Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.... Read more
Affected Products : meeting_sdk- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1369
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-For... Read more
Affected Products : security_guardium_big_data_intelligence- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-45210
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.... Read more
Affected Products : jeecg_boot- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
4.3
MEDIUMCVE-2010-2043
Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary). NOTE: some of these details are ob... Read more
Affected Products : datatrack_system- Published: May. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-20485
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X... Read more
Affected Products : sterling_file_gateway- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2617
Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.... Read more
Affected Products : php_bible_search- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4745
Cross-site scripting (XSS) vulnerability in nav.html in PHPXref before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : phpxref- Published: Feb. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-4323
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."... Read more
Affected Products : appscan- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0496
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascad... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-35800
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to in... Read more
Affected Products : endpoint_security- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1666
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on... Read more
Affected Products : datapower_gateway- Published: Feb. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6809
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cfg[projectName] parameter to index.php/admin/saveConfig, the (2) data[stats_provider_url] parameter to in... Read more
Affected Products : bedita- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-3614
Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file. ... Read more
- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6418
The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake ke... Read more
- Published: Dec. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-2084
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plu... Read more
Affected Products : essential_blocks- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10495
CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.... Read more
Affected Products : phpkb- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6625
System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and consequently gain privileges via a crafted application, aka internal bug 23936840.... Read more
Affected Products : android- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025