Latest CVE Feed
-
4.0
MEDIUMCVE-2007-5232
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the... Read more
- Published: Oct. 05, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2005-3975
Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed b... Read more
Affected Products : drupal- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2011-1687
Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote authenticated users to obtain sensitive information by using the search interface, as demonstrated by retrieving encrypted passwords.... Read more
- Published: Apr. 22, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2019-18458
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).... Read more
Affected Products : gitlab- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-18900
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affec... Read more
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-43217
The issue was addressed by adding additional logic. This issue is fixed in iPadOS 17.7.9, iOS 18.6 and iPadOS 18.6. Privacy Indicators for microphone or camera access may not be correctly displayed.... Read more
- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2010-3836
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors related to view preparation, pre-evaluation of LIKE predicates, and IN Optimiz... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-1319
The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) t... Read more
Affected Products : websphere_application_server- Published: Mar. 08, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-3451
PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.... Read more
Affected Products : phpwebgallery- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-0173
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpe... Read more
Affected Products : enterprise_collaboration- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2019-2941
Vulnerability in the Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Modeling). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access vi... Read more
Affected Products : hyperion_enterprise_performance_management_architect- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4177
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.... Read more
Affected Products : cognos_controller- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4398
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.... Read more
- Published: Oct. 24, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4112
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.... Read more
Affected Products : websphere_extreme_scale- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-32793
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that ori... Read more
Affected Products : cilium- Published: Apr. 21, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Race Condition
-
4.0
MEDIUMCVE-2025-26417
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges ... Read more
Affected Products : android- Published: Aug. 26, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2019-4161
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 158660.... Read more
Affected Products : security_information_queue- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2008-3059
member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffi... Read more
Affected Products : oempro- Published: Dec. 03, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-1119
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0616
Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."... Read more
- Published: Feb. 09, 2006
- Modified: Apr. 03, 2025