Latest CVE Feed
-
4.3
MEDIUMCVE-2025-8103
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for u... Read more
Affected Products : wpematico_rss_feed_fetcher- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2007-4161
rvd in TIBCO Rendezvous (RV) 7.5.2, when -no-lead-wc is omitted, might allow remote attackers to cause a denial of service (network instability) via a subject name with a leading (1) '*' (asterisk) or (2) '>' (greater than) wildcard character.... Read more
Affected Products : rendezvous- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1781
Multiple cross-site scripting (XSS) vulnerabilities in ajax/commentajax.php in SocialCMS 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) TREF_email_address or (2) TR_name parameters.... Read more
Affected Products : socialcms- Published: Mar. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-4151
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote attackers to obtain sensitive information via (1) a LOG.ON command, which reveals the logging pathname in the server response; (2) a VER command, which reveals the v... Read more
Affected Products : audit- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0663
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5629
Cross-site scripting (XSS) vulnerability in admin/logon.asp in ShoppingTree CandyPress Store 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2007-2804. NOTE: the provenance of this inf... Read more
Affected Products : candypress_store- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4063
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Fo... Read more
Affected Products : drupal- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4071
Multiple cross-site scripting (XSS) vulnerabilities in uploader/index.php in Webbler CMS before 3.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) login parameter.... Read more
Affected Products : webbler_cms- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4087
AlstraSoft Video Share Enterprise allows remote attackers to obtain sensitive information (the full path) via (1) a ' (quote) character in the category parameter to view_video.php, or (2) an XSS sequence in the UID parameter to (a) uprofile.php, (b) chann... Read more
Affected Products : video_share_enterprise- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4077
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Video Share Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) msg, (2) page, (3) viewkey, or (4) viewtype parameter to (a) view_video.php; the (5) next pa... Read more
Affected Products : video_share_enterprise- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4036
Guidance Software EnCase allows user-assisted remote attackers to cause a denial of service via (1) a corrupted Microsoft Exchange database, which triggers an application crash when many options are selected; (2) a corrupted NTFS filesystem, which causes ... Read more
Affected Products : encase- Published: Jul. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4025
Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.... Read more
Affected Products : java_system_application_server- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4024
Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: the provenance of this information is unknown; the details are o... Read more
Affected Products : philboard- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5673
Cross-site scripting (XSS) vulnerability in cgi-bin/webif.exe in ifnet WebIf allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.... Read more
Affected Products : webif- Published: Oct. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-1753
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.... Read more
Affected Products : security_key_lifecycle_manager- Published: Oct. 08, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5647
Multiple cross-site scripting (XSS) vulnerabilities in SocketKB 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) art_id or (2) node parameter in an article action to the default URI.... Read more
Affected Products : socketkb- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4014
Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via t... Read more
- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3875
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" ... Read more
- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3978
Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.... Read more
Affected Products : bwired- Published: Jul. 25, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-0518
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickj... Read more
Affected Products : sterling_secure_proxy- Published: May. 10, 2013
- Modified: Apr. 11, 2025