Latest CVE Feed
-
4.0
MEDIUMCVE-2015-0548
The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrict... Read more
Affected Products : documentum_d2- Published: Jul. 04, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2017-10033
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Supported versions that are affected are 11.1.1.8.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with lo... Read more
Affected Products : webcenter_sites- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2015-2599
Unspecified vulnerability in the RDBMS Scheduler component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
Affected Products : database_server- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2023-23003
In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value.... Read more
Affected Products : linux_kernel- Published: Mar. 01, 2023
- Modified: Mar. 20, 2025
-
4.0
MEDIUMCVE-2013-5757
Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx.... Read more
Affected Products : sip-t38g- Published: Aug. 03, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2022-34354
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424. ... Read more
- Published: Nov. 16, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-4807
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.... Read more
Affected Products : sterling_selling_and_fulfillment_foundation- Published: Nov. 23, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-8007
Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019.... Read more
Affected Products : prime_infrastructure- Published: Dec. 20, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2010-0928
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easie... Read more
- Published: Mar. 05, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2018-20405
BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system ... Read more
- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2022-36856
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.... Read more
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-0463
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors rela... Read more
Affected Products : supply_chain_products_suite- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-5905
Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.... Read more
Affected Products : knftpd- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-2173
The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.... Read more
Affected Products : websphere_portal- Published: May. 26, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2022-48470
Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability has been assigned... Read more
Affected Products :- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
4.0
MEDIUMCVE-2015-2657
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Business Process... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2025-53604
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.... Read more
Affected Products :- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
4.0
MEDIUMCVE-2012-6100
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess v... Read more
Affected Products : moodle- Published: Jan. 27, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2025-20909
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.... Read more
Affected Products : android- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
-
4.0
MEDIUMCVE-2020-4811
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation.... Read more
Affected Products : cloud_pak_for_security- Published: May. 14, 2021
- Modified: Nov. 21, 2024