Latest CVE Feed
-
5.4
MEDIUMCVE-2025-53631
flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post... Read more
Affected Products : flaskblog- Published: Aug. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2014-6767
The Juggle! FREE (aka com.jakyl.juggleforfree) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : juggle\!_free- EPSS Score: %0.04
- Published: Sep. 28, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2004-2527
The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Win... Read more
- EPSS Score: %1.00
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2005-3899
The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory duri... Read more
Affected Products : talk- EPSS Score: %1.15
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2005-3887
Gadu-Gadu 7.20 does not properly handle MS-DOS device names in filenames, which allows remote attackers to (1) cause a denial of service (hang) via an image filename of AUX: sent twice (hang), or (2) write to the LPT1 port via a filename of "LPT1:".... Read more
Affected Products : gadu-gadu_instant_messenger- EPSS Score: %1.41
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-3351
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL a... Read more
- EPSS Score: %25.50
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-4139
Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via unspecified vectors related to ifconfig and either netstat or SNMP queries.... Read more
Affected Products : solaris- EPSS Score: %0.76
- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-5179
Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra ti... Read more
- EPSS Score: %0.33
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2006-6896
The Bluetooth stack in the Plantronic Headset does not properly implement Non-pairable mode, which allows remote attackers to conduct unauthorized pair-up operations.... Read more
Affected Products : headset- EPSS Score: %0.31
- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2007-0661
Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 2007011... Read more
- EPSS Score: %0.36
- Published: Feb. 01, 2007
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2023-27070
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.... Read more
Affected Products : openplatform- EPSS Score: %0.09
- Published: Mar. 14, 2023
- Modified: Feb. 27, 2025
-
5.4
MEDIUMCVE-2014-7491
The Short Stories (aka com.ireadercity.c48) application 3.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : short_stories- EPSS Score: %0.04
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2009-2458
Unspecified vulnerability in Sun Fire V215 Server, when using XVR-100 graphic cards on system boards with part number 375-3463 and a hardware dash level -04 or later, allows remote attackers to cause a denial of service (panic) via unknown vectors.... Read more
Affected Products : sun_fire_server- EPSS Score: %0.69
- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2009-5098
The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating... Read more
Affected Products : palm_pre_webos- EPSS Score: %19.82
- Published: Sep. 13, 2011
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2013-4669
FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with... Read more
Affected Products : android linux_kernel mac_os_x windows forticlient forticlient_lite forticlient_ssl_vpn- EPSS Score: %0.13
- Published: Jun. 25, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2012-4094
Buffer overflow in the Smart Call Home feature in the fabric interconnect in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service by reading and forging control messages associated with Smart Call Home reports, aka Bug... Read more
Affected Products : unified_computing_system- EPSS Score: %0.84
- Published: Sep. 24, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2020-21101
Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code.... Read more
Affected Products : screenly- EPSS Score: %0.25
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-5223
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3... Read more
- Actively Exploited
- EPSS Score: %35.46
- Published: Nov. 19, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2013-6693
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345... Read more
- EPSS Score: %0.37
- Published: Nov. 22, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2013-7308
The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2.20.B017 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows ... Read more
- EPSS Score: %0.04
- Published: Jan. 23, 2014
- Modified: Apr. 11, 2025