Latest CVE Feed
-
4.3
MEDIUMCVE-2024-29093
Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3. ... Read more
Affected Products :- Published: Mar. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3869
Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote attackers to inject arbitrary web script or HTML via the subpage parameter to index.php.... Read more
Affected Products : redaxo- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-6772
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by ... Read more
Affected Products : elastic_services_controller- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-2181
Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to inject arbitrary web script or HTML via a file name.... Read more
- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1590
Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable... Read more
Affected Products : vp-asp_shopping_cart- Published: Apr. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3605
Cross-site scripting (XSS) vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3607
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : real_estate_portal- Published: Sep. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3471
The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.... Read more
Affected Products : identity_services_engine_software- Published: Aug. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-1593
Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter.... Read more
Affected Products : campus_pipeline- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-13511
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted ... Read more
- Published: Aug. 15, 2019
- Modified: Dec. 17, 2024
-
4.3
MEDIUMCVE-2014-2236
Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) user search forms.... Read more
Affected Products : askbot- Published: Mar. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-4335
Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action.... Read more
- Published: Nov. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5795
Cross-site scripting (XSS) vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5435
Cross-site scripting (XSS) vulnerability in moderate.php in PunBB before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via a topic subject.... Read more
Affected Products : punbb- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-56227
Missing Authorization vulnerability in WP Royal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.... Read more
Affected Products : royal_elementor_addons- Published: Dec. 31, 2024
- Modified: Mar. 21, 2025
-
4.3
MEDIUMCVE-2008-5842
Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via vectors associated with (1) a demo application shipped with WebT... Read more
Affected Products : webtransactions- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6127
Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) index.php, (3) cat and (4) file parameters to (b) download.p... Read more
Affected Products : mozilocms- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-14829
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mo... Read more
Affected Products : moodle- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-29891
Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Custom App via unspecified vectors.... Read more
Affected Products : office- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32516
Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5. ... Read more
Affected Products : multi_currency_for_woocommerce- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024