Latest CVE Feed
-
4.3
MEDIUMCVE-2024-21684
There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open re... Read more
Affected Products : bitbucket_data_center- Published: Jul. 24, 2024
- Modified: Jul. 30, 2025
-
4.3
MEDIUMCVE-2024-21665
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. ... Read more
Affected Products : e-commerce_framework- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-4667
Multiple cross-site scripting (XSS) vulnerabilities in SquidClamav 5.x before 5.8 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) virus, (3) source, or (4) user parameter to (a) clwarn.cgi, (b) clwarn.cgi.de_DE, (c) clwa... Read more
Affected Products : squidclamav- Published: Aug. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5368
phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.... Read more
Affected Products : phpmyadmin- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4651
Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.... Read more
Affected Products : ios- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5322
Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2) host_name_txtbox parameter to webconfig/lan/lan_conf... Read more
Affected Products : x7968- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-5307
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.... Read more
Affected Products : endpoint_protection_manager- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5279
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.... Read more
Affected Products : firefox- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4602
Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow remote attackers to inject arbitrary web script or HTML via the (1) cid or (2) uids parameter.... Read more
Affected Products : tcexam- Published: Nov. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1238
Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
Affected Products : sencha_sns- Published: Apr. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5341
Multiple cross-site scripting (XSS) vulnerabilities in statistik.php in Otterware StatIt 4 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter, (2) show parameter in a stat_tld action, or (3) order parameter in a sta... Read more
Affected Products : statit- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1224
Cross-site scripting (XSS) vulnerability in system/classes/login.php in ContentLion Alpha 1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : contentlion_alpha- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1219
Multiple cross-site scripting (XSS) vulnerabilities in freelancerKit 2.35 allow remote attackers to inject arbitrary web script or HTML via the (1) ticket parameter to tickets.php, (2) title parameter to notes.php, or (3) task parameter to todo.php. NOTE... Read more
Affected Products : freelancerkit- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1213
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.... Read more
Affected Products : zimbra- Published: Feb. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5384
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5... Read more
Affected Products : webcalendar- Published: Oct. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1161
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results... Read more
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5456
The Zoner AntiVirus Free application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrar... Read more
Affected Products : zoner_antivirus_free- Published: Oct. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4989
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the parent parameter in an info action.... Read more
Affected Products : openx- Published: Oct. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5105
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php.... Read more
Affected Products : sqlitemanager- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4970
Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspec... Read more
- Published: Jan. 01, 2013
- Modified: Apr. 11, 2025