Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4858
Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters associated with the (1) name, (2) title, and (3) comment sec... Read more
Affected Products : mimicboard_2- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2115
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.... Read more
Affected Products : power_editor- Published: May. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-20106
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a... Read more
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2072
Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or HTML via the l parameter, a different vector than CVE-2006-3260.... Read more
Affected Products : vlbook- Published: May. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-20142
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.... Read more
Affected Products : gitlab- Published: Jan. 13, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6883
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with... Read more
Affected Products : easy_social_feed- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2680
Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut parameters.... Read more
Affected Products : realm_cms- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-1854
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the w... Read more
Affected Products : telepresence_video_communication_server- Published: May. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6897
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it po... Read more
Affected Products : ean_for_woocommerce- Published: Apr. 18, 2024
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2009-2104
Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0456
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project... Read more
Affected Products : gitlab- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2445
Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a show action.... Read more
Affected Products : web_group_communication_center- Published: May. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1792
Cross-site scripting (XSS) vulnerability in the insertion filter in the Flickr Drupal module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-alpha allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4840
The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0494
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin par... Read more
Affected Products : mybulletinboard- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2458
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.... Read more
Affected Products : starsgames_control_panel- Published: May. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0407
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the orig... Read more
Affected Products : az_bulletin_board- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2166
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.... Read more
Affected Products : java_system_web_server- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2421
Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default ... Read more
- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2419
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSfram... Read more
Affected Products : firefox- Published: May. 23, 2008
- Modified: Apr. 09, 2025