Latest CVE Feed
-
4.3
MEDIUMCVE-2006-5717
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in sampl... Read more
Affected Products : zend_google_data_client_library_preview- Published: Nov. 04, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5713
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) author, (2) content, or (3) title parameters when posting a forum thread. NOTE: the provenance o... Read more
Affected Products : efs_web_server- Published: Nov. 04, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-3325
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2018-1025
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge.... Read more
- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0998
An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0892.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5652
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an I... Read more
Affected Products : iplanet_messaging_server_messenger_express- Published: Nov. 03, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2203
Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows remote attackers to inject arbitrary web script or HTML via the message field in the guestbook entry submission form.... Read more
Affected Products : guestbook- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2198
Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.... Read more
Affected Products : lan_management_system- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6307
Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header.... Read more
- Published: Dec. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-24128
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.... Read more
- Published: Jan. 27, 2025
- Modified: Jan. 31, 2025
-
4.3
MEDIUMCVE-2007-6320
Feature 4.7.x-dev and 5.x-dev before 20071206, a Drupal module, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks.... Read more
Affected Products : feature_module- Published: Dec. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4697
The Fast Forward feature in Opera before 9.61, when a page is located in a frame, executes a javascript: URL in the context of the outermost page instead of the page that contains this URL, which allows remote attackers to conduct cross-site scripting (XS... Read more
Affected Products : opera_browser- Published: Oct. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-51376
Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.... Read more
Affected Products : surefeedback- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6308
Cross-site scripting (XSS) vulnerability in HttpLogger 0.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : httplogger- Published: Dec. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-4902
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4905
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-43903
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.... Read more
Affected Products : poppler- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cryptography
-
4.3
MEDIUMCVE-2008-1399
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Clansphere 2008 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solel... Read more
- Published: Mar. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-5040
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-59040
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerabi... Read more
Affected Products : tuleap- Published: Sep. 18, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization