Latest CVE Feed
-
4.0
MEDIUMCVE-2007-3018
activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.... Read more
Affected Products : contentserver- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2025-43203
The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image in the most recently viewed locked note.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2006-6964
MailEnable Professional before 1.78 provides a cleartext user password when an administrator edits the user's settings, which allows remote authenticated administrators to obtain sensitive information by viewing the HTML source.... Read more
Affected Products : mailenable_professional- Published: Jan. 29, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2007-2407
The Samba server on Apple Mac OS X 10.3.9 and 10.4.10, when Windows file sharing is enabled, does not enforce disk quotas after dropping privileges, which allows remote authenticated users to use disk space in excess of quota.... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2007-1642
Unspecified vulnerability in ManageEngine Firewall Analyzer allows remote authenticated users to "access any common file" via a direct URL request.... Read more
- Published: Mar. 24, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2007-3017
The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admi... Read more
Affected Products : contentserver- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2025-32793
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that ori... Read more
Affected Products : cilium- Published: Apr. 21, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Race Condition
-
4.0
MEDIUMCVE-2019-4177
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.... Read more
Affected Products : cognos_controller- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-1999-0669
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.... Read more
Affected Products : internet_explorer- Published: Sep. 01, 1999
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0787
wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false info... Read more
Affected Products : wimpy_mp3- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-3451
PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.... Read more
Affected Products : phpwebgallery- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2019-4161
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 158660.... Read more
Affected Products : security_information_queue- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-2941
Vulnerability in the Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Modeling). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access vi... Read more
Affected Products : hyperion_enterprise_performance_management_architect- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2008-4500
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".... Read more
- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2019-4112
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.... Read more
Affected Products : websphere_extreme_scale- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2009-1873
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.... Read more
Affected Products : jrun- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2010-4549
IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation.... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2020-15185
In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repos... Read more
Affected Products : helm- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-3166
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-5034
IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous pr... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025