Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4665
Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.... Read more
Affected Products : punbb- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4583
Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).... Read more
Affected Products : esx- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-1311
Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAV... Read more
- Published: Apr. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4627
Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4663
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : ocomon- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4655
Cross-site scripting (XSS) vulnerability in submit.php in PHP-Fusion 6.0.204 allows remote attackers to inject arbitrary web script or HTML via nested tags in the news_body parameter, as demonstrated by elements such as "<me<meta>ta" and "<sc<script>ript>... Read more
Affected Products : php_fusion- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3301
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.... Read more
Affected Products : phpmyadmin- Published: Oct. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4780
Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Li... Read more
Affected Products : lighthouse_cms- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4785
Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section.... Read more
Affected Products : quickblogger- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-44116
The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impact on... Read more
Affected Products : netweaver_application_server_abap- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
4.3
MEDIUMCVE-2006-0365
Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.... Read more
Affected Products : xmb_forum- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0050
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.... Read more
Affected Products : lasso- Published: Jan. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0498
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-39868
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.... Read more
Affected Products : gitlab- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43780
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.... Read more
- Published: Aug. 22, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2021-39905
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with... Read more
Affected Products : gitlab- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39934
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43731
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a... Read more
- Published: Dec. 10, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2006-0461
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).... Read more
Affected Products : expressionengine- Published: Jan. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-57885
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support allows Cross Site Request Forgery. This issue affects Fluent Support: from n/a through 1.9.1.... Read more
Affected Products : fluent_support- Published: Aug. 22, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Request Forgery