Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2937
Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.... Read more
- Published: Sep. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6674
Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.... Read more
Affected Products : database- Published: Jan. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0618
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified ... Read more
Affected Products : dmsguestbook- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-19255
GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.... Read more
Affected Products : gitlab- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0623
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.... Read more
Affected Products : music_jukebox- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6669
Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter.... Read more
Affected Products : phcdownload- Published: Jan. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-24698
Cross-Site Request Forgery (CSRF) vulnerability in G5Theme Essential Real Estate allows Cross Site Request Forgery. This issue affects Essential Real Estate: from n/a through 5.1.8.... Read more
Affected Products : essential_real_estate- Published: Jan. 24, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-24691
Missing Authorization vulnerability in Gagan Sandhu , Enej Bajgoric , CTLT DEV, UBC People Lists allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects People Lists: from n/a through 1.3.10.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24682
Missing Authorization vulnerability in mikemmx Super Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Super Block Slider: from n/a through 2.7.9.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-0593
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read ... Read more
- Published: Feb. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-2769
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.... Read more
- Published: Dec. 23, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-0214
A vulnerability was found in TMD Custom Header Menu 4.0.0.1 on OpenCart. It has been rated as problematic. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument headermenu_id leads to sql injection. The ... Read more
Affected Products :- Published: Jan. 04, 2025
- Modified: Jan. 04, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2019-1645
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms for c... Read more
Affected Products : connected_mobile_experiences- Published: Jan. 24, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-31525
Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Mobile Bottom Menu: from n/a through 1.2.9.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24623
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Security Really Simple SSL allows Cross Site Request Forgery. This issue affects Really Simple SSL: from n/a through 9.1.4.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2019-19263
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.... Read more
Affected Products : gitlab- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-31753
Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser. This issue affects Advanced Speed Increaser: from n/a through 2.2.1.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-0400
Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.... Read more
- Published: Jan. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-30990
Missing Authorization vulnerability in ThemeHunk ThemeHunk allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThemeHunk: from n/a through 1.1.1.... Read more
Affected Products : mega_menu- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-30980
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link allows Cross Site Request Forgery. This issue affects Simple Keyword to Link: from n/a through 1.5.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery