Latest CVE Feed
-
4.3
MEDIUMCVE-2011-3189
The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE... Read more
Affected Products : php- Published: Aug. 25, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-2910
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with ne... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-7318
Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : firewall_analyzer- Published: Jan. 29, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2976
Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving a BUGLIST cookie.... Read more
Affected Products : bugzilla- Published: Aug. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-5638
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, whic... Read more
- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-3356
Multiple cross-site scripting (XSS) vulnerabilities in config_defaults_inc.php in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO, as demonstrated by the PATH_INFO to (1) manage_config_email_page.php, ... Read more
Affected Products : mantisbt- Published: Sep. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2937
Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.... Read more
- Published: Sep. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3366
Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.... Read more
Affected Products : rekonq- Published: Nov. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3426
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.... Read more
Affected Products : iphone_os- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6558
TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288.... Read more
Affected Products : totalplayer- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-15650
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.... Read more
Affected Products : easy_updates_manager- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-17138
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : foxit_studio_photo- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-19255
GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.... Read more
Affected Products : gitlab- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3875
Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.... Read more
Affected Products : chrome- Published: Oct. 25, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-1432
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine SupportCenter Plus 7.0.0 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, a related issue to CVE-2008-1299. NOTE: the provenance of ... Read more
Affected Products : supportcenter_plus- Published: Mar. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-19004
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6599
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAl... Read more
- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-54596
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accounts.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2013-1438
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop,... Read more
- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3375
content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection functio... Read more
Affected Products : firefox- Published: Oct. 29, 2009
- Modified: Apr. 09, 2025