Latest CVE Feed
-
4.3
MEDIUMCVE-2015-0724
Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12 in Cisco Headend Digital Broadband Delivery System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID C... Read more
Affected Products : headend_digital_broadband_delivery_system- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3989
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.... Read more
Affected Products : concrete5- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-0736
Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : pebble- Published: Feb. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-1911
Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remot... Read more
Affected Products : sterling_order_management sterling_selling_and_fulfillment_foundation sterling_field_sales- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-18445
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0961
Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : web_filter- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0962
Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle at... Read more
Affected Products : web_filter- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4084
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value_ parameter in a check_stat action to wp-admin/admin-ajax.php.... Read more
Affected Products : free_counter- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1389
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4138
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which makes it easier for remote attacke... Read more
Affected Products : ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv2800 ssl_visibility_appliance_sv1800 ssl_visibility_appliance_sv3800 ssl_visibility_appliance_sv800- Published: May. 30, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2948
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : zenphoto- Published: May. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-16251
A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input parameters are filtered, e.g., the /admin/user/users Nickname, email, firstname, lastname, and groupe parameters.... Read more
Affected Products : witycms- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2949
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : zenphoto- Published: May. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2944
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlRe... Read more
- Published: Jun. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-4802
Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained sol... Read more
Affected Products : blog- Published: Oct. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-0762
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for Microsoft Outlook allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu514... Read more
Affected Products : unified_meetingplace- Published: Jun. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-0540
Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and possibly other versions before 5.5 SP1, allows remote attackers to inject arbitrary web script or HTML via the search term field.... Read more
Affected Products : libero- Published: Feb. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-0774
Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5.5(9) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu70650.... Read more
Affected Products : application_and_content_networking_system_software- Published: Jun. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-0594
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : phpskelsite- Published: Feb. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-10835
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024