Latest CVE Feed
-
4.0
MEDIUMCVE-2014-9247
Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role information by visiting the ZenUsers (aka User Manager) page, aka ZEN-15389.... Read more
Affected Products : zenoss_core- Published: Dec. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9684
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 ... Read more
- Published: Feb. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-16237
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.... Read more
Affected Products : damicms- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-1568
IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.... Read more
- Published: Dec. 05, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-9354
NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related to cleartext storage.... Read more
Affected Products : oncommand_balance- Published: Feb. 06, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2022-39894
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.... Read more
- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-4991
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a du... Read more
Affected Products : spss_modeler- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-4495
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.... Read more
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-4786
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2021-25524
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.... Read more
Affected Products : contacts- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-7234
The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology and OSF Import modules are enabled, allows user-assisted remote attackers to delete arbitrary files via unspecified vectors.... Read more
Affected Products : open_semantic_framework- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9577
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.... Read more
Affected Products : vdg_sense- Published: Jan. 08, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0661
The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858.... Read more
Affected Products : ios_xr- Published: Mar. 06, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-20938
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-8391
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.... Read more
Affected Products : sendio- Published: Jun. 02, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path... Read more
Affected Products : thecartpress_ecommerce_shopping_cart- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6347
The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.... Read more
- Published: Oct. 30, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4543
EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remote authenticated users to obtain sensitive information by reading database fields.... Read more
Affected Products : rsa_archer_grc- Published: Sep. 26, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4876
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via unknown vectors related to Pivot Grid.... Read more
Affected Products : peoplesoft_products- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4162
XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.... Read more
Affected Products : pan-os- Published: Jun. 02, 2015
- Modified: Apr. 12, 2025