Latest CVE Feed
-
4.3
MEDIUMCVE-2007-6390
Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.... Read more
- Published: Dec. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-31942
Cross-Site Request Forgery (CSRF) vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through 3.0.2. ... Read more
Affected Products : calendarista- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-24711
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11. ... Read more
Affected Products : woocommerce_conversion_tracking- Published: Mar. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3779
PHP local file inclusion vulnerability in gpg_pop_init.php in the G/PGP (GPG) Plugin before 20070707 for Squirrelmail allows remote attackers to include and execute arbitrary local files, related to the MOD parameter.... Read more
Affected Products : gpg_plugin- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-6542
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.... Read more
- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1116
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.... Read more
Affected Products : campaign- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-6572
Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web ... Read more
- Published: Jun. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4611
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rsa_adaptive_authentication_on-premise- Published: Nov. 27, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5193
Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.... Read more
Affected Products : philboard- Published: Nov. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5428
Opera 9.51 on Windows XP does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stac... Read more
- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4242
Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.... Read more
Affected Products : turba_h3- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-5916
Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the WP e-Commerce plugin, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.... Read more
Affected Products : bradesco_gateway- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-6707
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-20... Read more
Affected Products : wag54gs- Published: Mar. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-47715
IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.... Read more
Affected Products : storage_protect_plus- Published: Mar. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5356
Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter.... Read more
- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4023
Cross-site scripting (XSS) vulnerability in the login CGI program in Aruba Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier FIPS versions, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mobility_controller- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6659
Multiple cross-site scripting (XSS) vulnerabilities in 2z project 0.9.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) contentshort or (2) contentfull parameter in an addnews action to the default URI; (3) the content paramete... Read more
Affected Products : 2z_project- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0967
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.... Read more
Affected Products :- Published: Mar. 01, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4592
The Mobile Network Connections functionality in the Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly handle failed attempts at establishing HTTP-TCP sessions, which allows remot... Read more
Affected Products : lotus_mobile_connect- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1506
Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.... Read more
Affected Products : application_server_portal- Published: Mar. 19, 2007
- Modified: Apr. 09, 2025