Latest CVE Feed
-
4.0
MEDIUMCVE-2020-6306
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).... Read more
Affected Products : leasing- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-53174
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.... Read more
Affected Products : harmonyos- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
4.0
MEDIUMCVE-2020-3930
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.... Read more
- Published: Jun. 12, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-0680
Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.... Read more
Affected Products : unified_callmanager- Published: Mar. 28, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-8079
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to header background setting.... Read more
- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6362
The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640... Read more
Affected Products : connected_grid_network_management_system- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-5427
Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518.... Read more
Affected Products : ios- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-0678
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly represent WebNavigator credentials in a database, which makes it easier for remote authenticated users to obtain sensitive information via a SQL query.... Read more
- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-0661
The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858.... Read more
Affected Products : ios_xr- Published: Mar. 06, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-2460
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, 6.2, 6.3, 6.3.1, 6.3.2, and 6.3.3 allows remote authenticated users to affect confidentiality via vectors related to CSV Ma... Read more
Affected Products : supply_chain_products_suite- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3379
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified... Read more
Affected Products : views- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-2180
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.... Read more
Affected Products : unified_contact_center_enterprise unified_contact_center_express_editor_software- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2071
Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filepath parameter.... Read more
Affected Products : samepage- Published: Feb. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-1881
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 ... Read more
- Published: Feb. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-4502
The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.... Read more
- Published: May. 13, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0620
The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.... Read more
Affected Products : telepresence_management_suite- Published: Feb. 18, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-5375
The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner matches the submitting user, which allows remote authenticated users to impersonate arbitrary users via the UserId and Owner tags.... Read more
Affected Products : moab- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9466
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the ... Read more
Affected Products : open-xchange_appsuite- Published: Feb. 17, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2017-18393
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-18395
cPanel before 68.0.15 does not block a username of ssl (SEC-328).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024