Latest CVE Feed
-
6.5
MEDIUMCVE-2021-37177
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected... Read more
Affected Products : sinema_remote_connect_server- Published: Sep. 14, 2021
- Modified: Apr. 23, 2025
-
10.0
HIGHCVE-2021-27391
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >=... Read more
Affected Products : apogee_mbc_\(ppc\)_\(p2_ethernet\)_firmware apogee_mec_\(ppc\)_\(p2_ethernet\)_firmware apogee_pxc_bacnet_automation_controller_firmware apogee_pxc_compact_\(p2_ethernet\)_firmware apogee_pxc_modular_\(bacnet\)_firmware apogee_pxc_modular_\(p2_ethernet\)_firmware talon_tc_compact_\(bacnet\)_firmware talon_tc_modular_\(bacnet\)_firmware apogee_mbc_\(ppc\)_\(p2_ethernet\) apogee_mec_\(ppc\)_\(p2_ethernet\) +6 more products- Published: Sep. 14, 2021
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2020-35498
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denia... Read more
- Published: Feb. 11, 2021
- Modified: Apr. 23, 2025
-
7.4
HIGHCVE-2020-25638
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allo... Read more
- Published: Dec. 02, 2020
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2024-36390
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service... Read more
- Published: Jun. 02, 2024
- Modified: Apr. 23, 2025
-
6.4
MEDIUMCVE-2024-5520
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, aft... Read more
Affected Products : opencms- Published: May. 30, 2024
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2023-45596
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. This issue affects: AiLux imx6 bundle below ... Read more
Affected Products : imx6- Published: Mar. 05, 2024
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2023-38366
IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files... Read more
Affected Products : filenet_content_manager- Published: Mar. 01, 2024
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2023-50324
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.... Read more
Affected Products : cognos_command_center- Published: Mar. 01, 2024
- Modified: Apr. 23, 2025
-
6.5
MEDIUMCVE-2023-50312
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.... Read more
Affected Products : websphere_application_server- Published: Mar. 01, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-25836
There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : portal_for_arcgis- Published: Jul. 21, 2023
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2023-25831
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s br... Read more
Affected Products : portal_for_arcgis- Published: May. 09, 2023
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2024-3893
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in all versions up to, and including, 3.0... Read more
- Published: Apr. 25, 2024
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2023-25830
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s b... Read more
Affected Products : portal_for_arcgis- Published: May. 09, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-25905
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18. ... Read more
Affected Products : multi_step_form- Published: Feb. 21, 2024
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2024-34780
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 13, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-45217
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.... Read more
Affected Products : book_store_management_system- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2022-45122
Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable Type... Read more
Affected Products : movable_type- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-43468
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number... Read more
Affected Products : wordpress_popular_posts- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025