Latest CVE Feed
-
5.5
MEDIUMCVE-2024-20969
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via m... Read more
- EPSS Score: %0.08
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
4.4
MEDIUMCVE-2024-20959
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Ora... Read more
Affected Products : zfs_storage_appliance_kit- EPSS Score: %0.06
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
3.7
LOWCVE-2024-20955
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 2... Read more
- EPSS Score: %0.34
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2024-20938
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise O... Read more
Affected Products : istore- EPSS Score: %0.35
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2024-20936
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : one-to-one_fulfillment- EPSS Score: %0.36
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
2.3
LOWCVE-2024-20914
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Ora... Read more
Affected Products : zfs_storage_appliance_kit- EPSS Score: %0.10
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
2.7
LOWCVE-2024-20912
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle ... Read more
Affected Products : audit_vault_and_database_firewall- EPSS Score: %0.18
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
3.0
LOWCVE-2024-20910
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracl... Read more
Affected Products : audit_vault_and_database_firewall- EPSS Score: %0.29
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
9.3
CRITICALCVE-2024-1143
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.... Read more
Affected Products : central_dogma- EPSS Score: %0.28
- Published: Feb. 02, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2024-1077
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)... Read more
- EPSS Score: %0.64
- Published: Jan. 30, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-51812
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.... Read more
- EPSS Score: %1.36
- Published: Jan. 04, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-50933
IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113. ... Read more
Affected Products : powersc- EPSS Score: %0.05
- Published: Feb. 02, 2024
- Modified: Jun. 03, 2025
-
7.1
HIGHCVE-2023-50342
HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result of improper access control. ... Read more
Affected Products : dryice_myxalytics- EPSS Score: %0.13
- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
7.1
HIGHCVE-2023-49739
Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23.... Read more
- EPSS Score: %0.19
- Published: Dec. 14, 2023
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-45718
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.... Read more
Affected Products : sametime- EPSS Score: %0.16
- Published: Feb. 09, 2024
- Modified: Jun. 03, 2025
-
4.1
MEDIUMCVE-2023-45716
Sametime is impacted by sensitive information passed in URL. ... Read more
Affected Products : sametime- EPSS Score: %0.05
- Published: Feb. 09, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-45696
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser. ... Read more
Affected Products : sametime- EPSS Score: %0.14
- Published: Feb. 10, 2024
- Modified: Jun. 03, 2025
-
6.1
MEDIUMCVE-2023-45190
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cr... Read more
Affected Products : engineering_lifecycle_optimization- EPSS Score: %0.05
- Published: Feb. 09, 2024
- Modified: Jun. 03, 2025
-
4.8
MEDIUMCVE-2023-37531
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access. ... Read more
Affected Products : bigfix_platform- Published: Feb. 29, 2024
- Modified: Jun. 03, 2025
-
5.4
MEDIUMCVE-2023-37530
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. ... Read more
Affected Products : bigfix_platform- Published: Feb. 29, 2024
- Modified: Jun. 03, 2025