Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10971
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.... Read more
Affected Products : devolutions_server- Published: Nov. 12, 2024
- Modified: Jun. 27, 2025
-
4.3
MEDIUMCVE-2008-4733
Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5... Read more
- Published: Oct. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-10321
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers... Read more
Affected Products : all-in-one_addons_for_elementor- Published: Mar. 08, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2006-2968
Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).... Read more
Affected Products : labwiki- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-2569
Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.htm... Read more
Affected Products : verlihub_control_panel- Published: Jul. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7185
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.... Read more
Affected Products : rhythmbox- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4394
Cross-site scripting (XSS) vulnerability in EPiX 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search query parameters.... Read more
Affected Products : epix- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-4065
Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.... Read more
- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5656
Cross-site scripting (XSS) vulnerability in the frontend plugin for the felogin system extension in TYPO3 4.2.0, 4.2.1 and 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : typo3- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5591
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained fro... Read more
Affected Products : nightfall_personal_diary- Published: Dec. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5584
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to ind... Read more
Affected Products : projectpier- Published: Dec. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5719
Cross-site scripting (XSS) vulnerability in Hitachi Groupmax Web Workflow SDK Set for Active Server Pages before 06-52-/C and Hitachi Groupmax Workflow - Development Kit for Active Server Pages before 06-52-/A allows remote attackers to inject arbitrary w... Read more
- Published: Dec. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5569
Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in ... Read more
Affected Products : phpeppershop- Published: Dec. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4805
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5)... Read more
Affected Products : lotus_connections- Published: Oct. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7205
Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file.... Read more
Affected Products : virtuemart- Published: Sep. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7175
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5290
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : clean_cms- Published: Dec. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5566
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : phpmultiplenewsletters- Published: Dec. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5555
Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain atta... Read more
Affected Products : internet_explorer- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2342
Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the username field.... Read more
Affected Products : cmme- Published: Jul. 07, 2009
- Modified: Apr. 09, 2025