Latest CVE Feed
-
4.0
MEDIUMCVE-2020-15184
In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. ... Read more
Affected Products : helm- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-3069
Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: Installation). The supported version that is affected is 6.2.0.0. Easily exploitable vulnerability allows high privil... Read more
Affected Products : agile_product_lifecycle_management_for_process- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-10194
Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows high privi... Read more
Affected Products : integrated_lights_out_manager_firmware- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2019-2789
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via m... Read more
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2023-28362
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Lo... Read more
Affected Products : actionpack- Published: Jan. 09, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2021-2152
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vu... Read more
Affected Products : business_intelligence- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-2544
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructur... Read more
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-20932
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-6089
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (disrupted system operations) by uploading a file to a pro... Read more
- Published: Dec. 18, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2017-18455
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-15663
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out-of-bounds read that can be used as part of a chain to e... Read more
Affected Products : killer_control_center- Published: Mar. 20, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-9577
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.... Read more
Affected Products : vdg_sense- Published: Jan. 08, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-4769
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity ref... Read more
Affected Products : websphere_commerce- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2019-19018
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.... Read more
Affected Products : webtitan- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-18395
cPanel before 68.0.15 does not block a username of ssl (SEC-328).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4296
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-18426
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-18393
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-20938
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-0487
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0488, CVE-2012-0489, CVE-2012... Read more
Affected Products : mysql- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025