Latest CVE Feed
-
4.3
MEDIUMCVE-2015-2165
Multiple cross-site scripting (XSS) vulnerabilities in the Report Viewer in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4.x, 5.x, and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) portal, (2) fromDate, (3) toDate... Read more
Affected Products : drutt_mobile_service_delivery_platform- Published: Apr. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0404
Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : documentum_eroom- Published: Mar. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-1245
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : mediawiki- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-1497
Unspecified vulnerability in the Oracle COREid Access component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to WebGate - WebServer plugin.... Read more
Affected Products : fusion_middleware- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-32090
Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27. ... Read more
Affected Products : church_admin- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4603
Cross-site scripting (XSS) vulnerability in printthread.php in MyBB 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a thread message, which is not properly sanitized in the print view of the thread.... Read more
Affected Products : mybulletinboard- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-4742
Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a pa... Read more
Affected Products : claroline- Published: Sep. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6575
Cross-site scripting (XSS) vulnerability in the Exposed Filter Data module 6.x-1.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 27, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-46600
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-32226
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accepted by the server, so that instead ... Read more
Affected Products : rocket.chat- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2007-4959
Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained... Read more
- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-1550
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via unknown vectors related to WorkCenter.... Read more
Affected Products : peoplesoft_products- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-5088
Cross-site scripting (XSS) vulnerability in search/cust_bill_event.cgi in Freeside 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the failed parameter.... Read more
Affected Products : freeside- Published: Sep. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5144
Buffer overflow in the GDI engine in Windows Live Messenger, as used for Windows MSN Live 8.1, allows user-assisted remote attackers to cause a denial of service (application crash or system crash) and possibly execute arbitrary code by placing a malforme... Read more
Affected Products : windows_live_messenger- Published: Oct. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5212
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf... Read more
- Published: Oct. 04, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2002-2056
Cross-site scripting (XSS) vulnerability in TeeKai Forum 1.2 allows remote attackers to inject arbitrary web script or HTML via the valid_username_online cookie.... Read more
Affected Products : teekai_forum- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5292
Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory parameter.... Read more
Affected Products : directory_image_gallery- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4848
Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resour... Read more
- Published: Sep. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4246
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in ... Read more
Affected Products : phplist- Published: Aug. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-23981
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).... Read more
Affected Products : perfect_brands_for_woocommerce- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024