Latest CVE Feed
-
4.0
MEDIUMCVE-2013-3057
Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and list the privileges of arbitrary users via unspecified vectors.... Read more
Affected Products : joomla\!- Published: May. 03, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3387
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.... Read more
Affected Products : moodle- Published: Jul. 23, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3864
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-4257
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA pack... Read more
Affected Products : db2- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2018-10423
mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.... Read more
- Published: Apr. 26, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-10424
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.... Read more
- Published: Apr. 26, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2023-21900
Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to com... Read more
- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-3187
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has... Read more
- Published: Aug. 12, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2016-0413
Unspecified vulnerability in the Oracle Identity Federation component in Oracle Fusion Middleware 11.1.1.7 allows remote authenticated users to affect integrity via vectors related to Federation protocol support.... Read more
Affected Products : fusion_middleware- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2021-47096
In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space file structure in the open function, because the file private structure use kma... Read more
Affected Products : linux_kernel- Published: Mar. 04, 2024
- Modified: Apr. 08, 2025
-
4.0
MEDIUMCVE-2018-10521
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-2600
Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.... Read more
- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2006-0309
Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.... Read more
Affected Products : befvp41- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2025-26417
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges ... Read more
Affected Products : android- Published: Aug. 26, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2010-4787
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-0173
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpe... Read more
Affected Products : enterprise_collaboration- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-3451
PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.... Read more
Affected Products : phpwebgallery- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2025-32793
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that ori... Read more
Affected Products : cilium- Published: Apr. 21, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Race Condition
-
4.0
MEDIUMCVE-2006-0174
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the ... Read more
- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-3059
member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffi... Read more
Affected Products : oempro- Published: Dec. 03, 2008
- Modified: Apr. 09, 2025