Latest CVE Feed
-
4.0
MEDIUMCVE-2018-20932
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-6584
Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite ILOM before 3.2.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Backup Restore.... Read more
Affected Products : integrated_lights_out_manager_firmware- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2017-18426
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-1991
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.... Read more
Affected Products : api_connect- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-18395
cPanel before 68.0.15 does not block a username of ssl (SEC-328).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-6362
The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640... Read more
Affected Products : connected_grid_network_management_system- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6371
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.... Read more
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6089
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (disrupted system operations) by uploading a file to a pro... Read more
- Published: Dec. 18, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8228
Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors.... Read more
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8229
Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.... Read more
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2017-18393
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-19421
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.... Read more
- Published: Nov. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-3042
IBM CICS Transaction Server 3.1, 3.2, 4.1, 4.2, and 5.1 on z/OS does not properly implement CEMT transactions, which allows remote authenticated users to cause a denial of service (storage overlay) by using a 3270 emulator to send an invalid 3270 data str... Read more
Affected Products : cics_transaction_server- Published: Jun. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-20938
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-4769
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity ref... Read more
Affected Products : websphere_commerce- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2019-5461
An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.1... Read more
Affected Products : gitlab- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2016-0234
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.... Read more
Affected Products : openpages_grc_platform- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2013-3428
The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that triggers an error, aka Bug ID CSCue65... Read more
Affected Products : secure_access_control_system- Published: Jul. 15, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2016-3021
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2015-0516
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025