Latest CVE Feed
-
4.0
MEDIUMCVE-2012-4400
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.... Read more
Affected Products : moodle- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-4890
The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a ROWNUM condition involving a subquery.... Read more
Affected Products : soliddb- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-3187
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has... Read more
- Published: Aug. 12, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-3491
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.... Read more
Affected Products : condor- Published: Sep. 28, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2020-6306
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).... Read more
Affected Products : leasing- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2010-4787
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2016-8579
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.... Read more
Affected Products : docker2aci- Published: Oct. 28, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2008-1728
ConnectionManagerImpl.java in Ignite Realtime Openfire 3.4.5 allows remote authenticated users to cause a denial of service (daemon outage) by triggering large outgoing queues without reading messages.... Read more
- Published: Apr. 11, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2025-53174
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.... Read more
Affected Products : harmonyos- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
4.0
MEDIUMCVE-2019-4177
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.... Read more
Affected Products : cognos_controller- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-0787
wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false info... Read more
Affected Products : wimpy_mp3- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2019-4398
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.... Read more
- Published: Oct. 24, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-26417
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges ... Read more
Affected Products : android- Published: Aug. 26, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2019-4161
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 158660.... Read more
Affected Products : security_information_queue- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-21033
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2008-2018
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authenticated users to obtain sensitive information via a comment containing a ma... Read more
Affected Products : phpizabi- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2019-4465
IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 163774.... Read more
Affected Products : cloud_pak_system- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4112
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.... Read more
Affected Products : websphere_extreme_scale- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-0981
Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.... Read more
Affected Products : e-merge_winace- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2020-14847
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via ... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024