Latest CVE Feed
-
4.0
MEDIUMCVE-2012-4083
Multiple buffer overflows in the administrative web interface in Cisco Unified Computing System (UCS) allow remote authenticated users to cause a denial of service (memory corruption and session termination) via long string values for unspecified paramete... Read more
Affected Products : unified_computing_system- Published: Sep. 20, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-6261
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP sessi... Read more
Affected Products : telepresence_video_communication_server_software- Published: Aug. 26, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-8079
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to header background setting.... Read more
- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4295
The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID CSCuv21819.... Read more
Affected Products : unified_communications_manager- Published: Aug. 01, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-5382
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383.... Read more
Affected Products : maximo_asset_management- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-8887
IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to upload arbitrary GIFAR files, and consequently modify data, via un... Read more
Affected Products : marketing_operations- Published: Jun. 07, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2118
Unspecified vulnerability in the Secure Pull Print and Security Pull Print components in HP Access Control (AC) Software 12.x through 14.x before 14.1.2 allows remote authenticated users to obtain sensitive information via unknown vectors.... Read more
Affected Products : access_control- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-5534
Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, vi... Read more
Affected Products : unity_connection- Published: Oct. 19, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-8391
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.... Read more
Affected Products : sendio- Published: Jun. 02, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3379
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified... Read more
Affected Products : views- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2021-20121
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary files from the device by preparing and connecting a spec... Read more
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-4889
IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.... Read more
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-3076
Vulnerability in the PeopleSoft Enterprise CS Financial Aid component of Oracle PeopleSoft Products (subcomponent: ISIR Processing). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows high privileged attacker wit... Read more
Affected Products : peoplesoft_enterprise_cs_financial_aid- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-22033
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2016-0234
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.... Read more
Affected Products : openpages_grc_platform- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-25523
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.... Read more
Affected Products : dialer- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-25939
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-priv... Read more
Affected Products : arangodb- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-21534
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to gain access to sensitive information via the local API.... Read more
Affected Products : hybrid_client- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-1717
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2023-20177
A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attack... Read more
Affected Products : firepower_threat_defense- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024