Latest CVE Feed
-
4.3
MEDIUMCVE-2022-23994
An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.... Read more
Affected Products : wear_os- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2965
Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : scopia- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-6785
A vulnerability in configuration modification permissions validation for Cisco Unified Communications Manager could allow an authenticated, remote attacker to perform a horizontal privilege escalation where one user can modify another user's configuration... Read more
Affected Products : unified_communications_manager- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2006-1428
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.... Read more
Affected Products : phpcoin- Published: Mar. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-36757
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthe... Read more
Affected Products : wp_hotel_booking- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-3851
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.... Read more
- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0231
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.... Read more
Affected Products : financial_transaction_manager- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5706
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater t... Read more
Affected Products : coursemill_learning_management_system- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0573
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx.... Read more
Affected Products : fotoweb- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6063
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Tempo... Read more
Affected Products : word- Published: Feb. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7132
Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.3 beta allows remote attackers to inject arbitrary web script or HTML via the nuked_nude parameter. NOTE: the provenance of this information is unknown; the details are obtained solely... Read more
Affected Products : nuked-klan- Published: Sep. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1855
Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows local users to read or modify (1) log files or (2) other data via unknown vectors.... Read more
Affected Products : network_node_manager_i- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-34626
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.... Read more
Affected Products : wp-upload-restriction- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-1620
Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name1, (2) email, or (3) cmt parameter.... Read more
Affected Products : hiox_guest_book- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1612
Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
- Published: Jan. 30, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-2408
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-3887
The Limit Mail feature in the Parental Controls functionality in Mail on Apple Mac OS X does not properly enforce the correspondence whitelist, which allows remote attackers to bypass intended access restrictions and conduct e-mail communication by levera... Read more
- Published: Oct. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-1369
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-For... Read more
Affected Products : security_guardium_big_data_intelligence- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10474
A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.... Read more
Affected Products : global_post_script- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-3844
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance s... Read more
Affected Products : prime_collaboration_assurance- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025