Latest CVE Feed
-
4.3
MEDIUMCVE-2010-3495
Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) before 3.10.0 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having a... Read more
Affected Products : zodb- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0404
Unspecified vulnerability in the Oracle Identity Federation component in Oracle Fusion Middleware 11.1.2.2 allows remote attackers to affect integrity via vectors related to Admin.... Read more
Affected Products : fusion_middleware- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6529
Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter to site/error.php or (2) ip parameter to site/tools/searchResults.php.... Read more
Affected Products : phpipam- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-4709
Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search pa... Read more
- Published: Dec. 08, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0398
IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.... Read more
Affected Products : cognos_analytics- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3037
Cross-site scripting (XSS) vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : address_directory- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1888
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited with... Read more
- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4830
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this coo... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-10218
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with netw... Read more
Affected Products : hospitality_guest_access- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-3506
Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.... Read more
Affected Products : cmsphp- Published: Oct. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-10132
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/iOS). The supported version that is affected is 1.05. Easily exploitable vulnerability allows low privileged attacker with network access via ... Read more
Affected Products : hospitality_hotel_mobile- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-5323
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.... Read more
Affected Products : wysi_wiki_wyg- Published: Dec. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2914
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; t... Read more
Affected Products : xzero_community_classifieds- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-26216
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.... Read more
Affected Products : seeddms- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-5424
The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" hea... Read more
Affected Products : outlook_express- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2002
Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : c-board_moyuku- Published: Jun. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-10008
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low pr... Read more
Affected Products : flexcube_private_banking- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-8751
Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress 13.00.06 allow remote attackers to inject arbitrary web script or HTML via the (1) search_param parameter to search.php or (2) name, (3) address, or (4) comment parameter to forms.php.... Read more
Affected Products : webpress- Published: Dec. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1647
Multiple cross-site scripting (XSS) vulnerabilities in the "stand alone PHP application for the OSM Player," as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal, allow remote attackers to inject arbitrary web scri... Read more
- Published: Aug. 28, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3916
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a child node title.... Read more
- Published: Nov. 09, 2009
- Modified: Apr. 09, 2025