Latest CVE Feed
-
4.3
MEDIUMCVE-2009-1588
Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 before 10.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : cgi_rescue_minibbs- Published: May. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-14838
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multipl... Read more
Affected Products : active_iq_unified_manager mysql oncommand_insight oncommand_workflow_automation snapcenter mysql_server- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4788
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings... Read more
Affected Products : pligg_cms- Published: Apr. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4220
Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecifie... Read more
Affected Products : websphere_application_server- Published: Nov. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-14581
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attack... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight oncommand_workflow_automation jdk jre +11 more products- Published: Jul. 15, 2020
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2010-3012
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue was originally assigned CVE-2010-3010 due to a CNA error.... Read more
Affected Products : system_management_homepage- Published: Sep. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4736
Cross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : commonsense_cms- Published: Mar. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10354
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.... Read more
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2014
Cross-site scripting (XSS) vulnerability in cp/list_content.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the cl or possibly id parameter.... Read more
Affected Products : lisk_cms- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1963
Cross-site scripting (XSS) vulnerability in HP ServiceCenter allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4729
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id... Read more
Affected Products : adult_script- Published: Mar. 18, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12027
The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateFilter() and deleteFilter() functions in all versions up to, and including, 1.6.3. This makes it p... Read more
Affected Products : message_filter_for_contact_form_7- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.3
MEDIUMCVE-2024-39413
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass securi... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
4.3
MEDIUMCVE-2011-5307
Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : photosmash- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-39301
A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network. We have already fixed the vulne... Read more
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1940
Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging ... Read more
- Published: May. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1581
functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting ... Read more
Affected Products : squirrelmail- Published: May. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-5257
Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter related to the Twitter widget and (2) facebook_id parame... Read more
- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3018
RSA Access Manager Server 5.5.3 before 5.5.3.172, 6.0.4 before 6.0.4.53, and 6.1 before 6.1.2.01 does not properly perform cache updates, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : access_manager_server- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12616
The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 2.7.3. This makes it possible for authenticated attac... Read more
Affected Products : bitly- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization