Latest CVE Feed
-
4.3
MEDIUMCVE-2005-0628
Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.... Read more
Affected Products : forumwa- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0985
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.... Read more
Affected Products : wordpress- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-2188
A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : amazon_ec2- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3368
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : search_enhanced- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3103
Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.... Read more
Affected Products : bitweaver- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-0896
Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than ... Read more
- Published: Feb. 13, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-0901
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.... Read more
Affected Products : nukebookmarks- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-7368
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id para... Read more
Affected Products : gnew- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-3361
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrat... Read more
Affected Products : ultimate_member- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-3737
Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.... Read more
Affected Products : plesk_control_panel- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-4904
Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0936
Cross-site scripting (XSS) vulnerability in EMC Smarts IP Manager, Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS Manager before 9.2 allows remote attackers to in... Read more
- Published: Mar. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1020
Cross-site scripting (XSS) vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 19, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-13292
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.... Read more
Affected Products : router_manager- Published: Apr. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3842
Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise Filter before 2.0.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this may be the same as CVE-2007-2970.... Read more
Affected Products : r3000_enterprise_filter- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1735
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : vidsharepro- Published: May. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10326
A cross-site request forgery vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attackers to reset warning counts for future builds.... Read more
Affected Products : warnings_next_generation- Published: May. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4704
IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the u... Read more
Affected Products : security_identity_manager_virtual_appliance- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2583
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.... Read more
Affected Products : mini_mail_dashboard_widget- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-3087
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m parameter in (a) common/galleries.asp; (6) aid, (7) ... Read more
Affected Products : ezgallery- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025