Latest CVE Feed
-
4.3
MEDIUMCVE-2012-6555
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title.... Read more
Affected Products : latestcomment- Published: May. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0068
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.... Read more
Affected Products : wireshark- Published: Apr. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4043
Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5 allows remote attackers to inject arbitrary web scri... Read more
- Published: Jul. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2393
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via (1) the lastusername parameter to index.php or (2) selected_search_arch parameter to search.php.... Read more
Affected Products : cutenews- Published: Jul. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-28166
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrit... Read more
- Published: Aug. 13, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2013-1418
The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash... Read more
- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-21206
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network ... Read more
Affected Products : enterprise_command_center_framework- Published: Oct. 15, 2024
- Modified: Jun. 23, 2025
-
4.3
MEDIUMCVE-2020-24982
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.... Read more
Affected Products : espressdashboard- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-1944
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.... Read more
Affected Products : ilch_cms- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4018
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.... Read more
Affected Products : mywebsearch- Published: Oct. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4016
The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.... Read more
- Published: Sep. 28, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6523
Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1) the p parameter in the getMenus function in codes/wcms.php; or the COMMENT parameter in (2) blog.php, (3) guestbook.php... Read more
Affected Products : w-cms- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-25025
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).... Read more
Affected Products : localization_manager- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-6534
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data rete... Read more
Affected Products : sentinel_log_manager- Published: Mar. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4013
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file... Read more
Affected Products : kunai_browser_for_remote_service- Published: Sep. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4012
The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a ... Read more
Affected Products : kunai- Published: Sep. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4019
Cross-site scripting (XSS) vulnerability in tokyo_bbs.cgi in Come on Girls Interface (CGI) Tokyo BBS allows remote attackers to inject arbitrary web script or HTML via vectors related to the error page.... Read more
Affected Products : tokyo_bbs- Published: Oct. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3997
Multiple cross-site scripting (XSS) vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to inject arbitrary web script or HTML via the (1) paste_user or (2) paste_lang parameter to (a) list.php or (b) show.php.... Read more
Affected Products : sticky_notes- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4000
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via ... Read more
Affected Products : fckeditor- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6566
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 17, 2013
- Modified: Apr. 11, 2025