Latest CVE Feed
-
4.3
MEDIUMCVE-2013-6903
Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-1559
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758.... Read more
- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6907
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1137
The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to passively observe data traffic to other clients. Affected releases are TIBCO Soft... Read more
Affected Products :- Published: Mar. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8296
Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : modal_frame- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-13461
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the ... Read more
Affected Products : securetrack- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2001-1524
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and st... Read more
Affected Products : php-nuke- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-25653
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI.... Read more
Affected Products :- Published: Mar. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-32219
An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (... Read more
Affected Products : rocket.chat- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2023-39933
Insufficient verification vulnerability exists in Broadcast Mail CGI (pmc.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a user who can upload files through the product may execute an arbitrary exe... Read more
Affected Products :- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-12825
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Do... Read more
Affected Products : gitlab- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-1522
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configure... Read more
Affected Products : connected_mobile_experiences- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-9352
Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_access- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9230
Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : data_loss_prevention- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-6810
The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated ... Read more
Affected Products :- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4704
IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the u... Read more
Affected Products : security_identity_manager_virtual_appliance- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-7348
Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to demo/en/asyncData/getNodesForBigData.php.... Read more
Affected Products : ztree- Published: Dec. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3842
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.... Read more
Affected Products : imember360- Published: May. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-2186
Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : chicomas- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2567
Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related... Read more
Affected Products : grani- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025