Latest CVE Feed
-
4.3
MEDIUMCVE-2009-1685
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML by overwriting the document.implement... Read more
Affected Products : safari- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-30260
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.... Read more
- Published: Apr. 04, 2024
- Modified: Feb. 13, 2025
-
4.3
MEDIUMCVE-2024-32804
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46.... Read more
Affected Products : gotowebinar- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1971
Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0... Read more
- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3422
Cross-site scripting (XSS) vulnerability in SearchBlox before 8.2.1 allows remote attackers to inject arbitrary web script or HTML via the menu2 parameter to admin/main.jsp.... Read more
Affected Products : searchblox- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-27807
The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. An app may be able to circumvent App Privacy Report logging.... Read more
- Published: Jun. 10, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2015-1067
Secure Transport in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafte... Read more
- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2434
Microsoft XML Core Services 3.0 and 5.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability,... Read more
Affected Products : xml_core_services- Published: Aug. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2440
Microsoft XML Core Services 3.0, 5.0, and 6.0 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "MSXML Information Disclosure Vulnerability."... Read more
Affected Products : xml_core_services- Published: Aug. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-4667
IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive information due to improper input validation. IBM X-Force ID: 186282.... Read more
Affected Products : engineering_requirements_quality_assistant_on-premises- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-35551
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.... Read more
- Published: May. 22, 2024
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-0051
Microsoft Internet Explorer 8 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."... Read more
Affected Products : internet_explorer- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-5565
Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'.... Read more
Affected Products : garoon- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8774
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.... Read more
Affected Products : modx_revolution- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8629
Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.... Read more
- Published: Nov. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8800
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_... Read more
Affected Products : nextend_facebook_connect- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0070
Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2646
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 11.1.0.1; EM Plugin for DB: 12.1.0.5, 12.1.0.6, 12.1.0.7; EM DB Control: 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows ... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8584
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web-dorado_spider_video_player- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0386
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener, a different vulnerability than CVE-201... Read more
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025