Latest CVE Feed
-
4.3
MEDIUMCVE-2024-21099
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visualization). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with n... Read more
Affected Products : business_intelligence- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2024-21076
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Offer LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP... Read more
Affected Products : trade_management- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2024-21074
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HT... Read more
Affected Products : trade_management- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
6.1
MEDIUMCVE-2024-21065
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access... Read more
- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2024-21064
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privilege... Read more
Affected Products : business_intelligence- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
6.1
MEDIUMCVE-2024-21063
Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with... Read more
Affected Products : peoplesoft_enterprise_hcm_benefits_administration- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
7.8
HIGHCVE-2022-42942
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in th... Read more
Affected Products : autocad autocad_architecture autocad_civil_3d autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d design_review +1 more products- EPSS Score: %0.14
- Published: Oct. 21, 2022
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2022-42233
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.... Read more
- EPSS Score: %86.61
- Published: Oct. 20, 2022
- Modified: May. 08, 2025
-
7.2
HIGHCVE-2022-42201
Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.... Read more
Affected Products : simple_exam_reviewer_management_system- EPSS Score: %0.10
- Published: Oct. 20, 2022
- Modified: May. 08, 2025
-
6.5
MEDIUMCVE-2022-2762
The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack... Read more
Affected Products : adminpad- EPSS Score: %0.19
- Published: Oct. 25, 2022
- Modified: May. 08, 2025
-
9.9
CRITICALCVE-2024-25909
Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2. ... Read more
Affected Products : wp_media_folder- Published: Feb. 26, 2024
- Modified: May. 08, 2025
-
8.8
HIGHCVE-2024-24310
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.... Read more
Affected Products : generate_barcode_on_invoice_\/_delivery_slip- Published: Feb. 23, 2024
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2024-24309
In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.... Read more
Affected Products : survey_tma- Published: Feb. 23, 2024
- Modified: May. 08, 2025
-
6.3
MEDIUMCVE-2024-22220
An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder an... Read more
- Published: Feb. 21, 2024
- Modified: May. 08, 2025
-
6.5
MEDIUMCVE-2020-17386
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.... Read more
Affected Products : cellos- EPSS Score: %0.33
- Published: Aug. 25, 2020
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2020-17385
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.... Read more
Affected Products : cellos- EPSS Score: %0.42
- Published: Aug. 25, 2020
- Modified: May. 08, 2025
-
9.0
HIGHCVE-2020-17384
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system.... Read more
Affected Products : cellos- EPSS Score: %0.45
- Published: Aug. 25, 2020
- Modified: May. 08, 2025
-
8.8
HIGHCVE-2024-25744
In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Feb. 12, 2024
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2023-49339
Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.... Read more
Affected Products : banner- EPSS Score: %0.18
- Published: Feb. 13, 2024
- Modified: May. 07, 2025
-
6.1
MEDIUMCVE-2023-45206
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malic... Read more
Affected Products : collaboration- EPSS Score: %0.35
- Published: Feb. 13, 2024
- Modified: May. 07, 2025