Latest CVE Feed
-
4.3
MEDIUMCVE-2009-3539
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.... Read more
Affected Products : ultra_classifieds_pro- Published: Oct. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2700
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : clickbank_affiliate_marketplace_script- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4507
Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-21095
Certain NETGEAR devices are affected by stored XSS. This affects SRR60 before 2.2.1.210 and SRS60 before 2.2.1.210.... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-3051
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.... Read more
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2007-6541
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action ... Read more
Affected Products : neuron_news- Published: Dec. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-3869
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access ... Read more
Affected Products : customer_reviews_for_woocommerce- Published: Apr. 16, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2007-2802
Cross-site scripting (XSS) vulnerability in cp/ps/Main/login/Login in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the d parameter.... Read more
Affected Products : rm_easymail_plus- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3010
Cross-site scripting (XSS) vulnerability on the HP 3Com OfficeConnect Gigabit VPN Firewall 3CREVF100-73 with firmware before 1.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: a separate XSS issue for HP ... Read more
- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-1768
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471.... Read more
Affected Products : security_guardium_big_data_intelligence- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4384
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.... Read more
Affected Products : campaign- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3616
Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : knowledgeview_editorial_and_management_application- Published: Sep. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-24569
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.... Read more
- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0906
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current, which allows remote attackers to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated co... Read more
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-8801
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level ac... Read more
Affected Products : happy_addons_for_elementor- Published: Sep. 25, 2024
- Modified: Sep. 30, 2024
-
4.3
MEDIUMCVE-2009-4408
Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to inject arbitrary web script or HTML via crafted BBcode (1) img or (2) url tags, which are n... Read more
- Published: Dec. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-39018
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726.... Read more
- Published: Jul. 14, 2022
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2017-2091
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.... Read more
Affected Products : garoon- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2007-6486
Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are o... Read more
Affected Products : lineshout- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-15935
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscati... Read more
Affected Products : fortiadc- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024