Latest CVE Feed
-
4.3
MEDIUMCVE-2007-2410
WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of certain global objects when a new URL is visited in the same window, which allows remote attackers to conduct cross-site scripting (XSS) attacks.... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2739
Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : xajax- Published: May. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2543
Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incor... Read more
Affected Products : cacti- Published: Aug. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6879
Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.... Read more
Affected Products : roller- Published: Jul. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7250
Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying t... Read more
Affected Products : sarg- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6054
Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INF... Read more
Affected Products : mc-800- Published: Nov. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2429
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not Found" response.... Read more
- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-1589
Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.... Read more
Affected Products : gosmart_message_board- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1599
Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.... Read more
Affected Products : coolphpweb_portal- Published: Oct. 16, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-2325
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL in... Read more
- Published: Jun. 18, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2301
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element.... Read more
- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.... Read more
Affected Products : ws_ftp- Published: Apr. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2002-1683
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.... Read more
Affected Products : badblue- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-2265
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr ... Read more
- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2121
Opera 9.52 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.... Read more
Affected Products : opera_browser- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4396
Cross-zone scripting vulnerability in the HandleAction method in a certain ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 allows remote attackers to inject arbitrary web scrip... Read more
- Published: Dec. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2032
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm ... Read more
Affected Products : resin- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3299
Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mahara- Published: Nov. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-48068
Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limited source code exposure when the dev server was running with the App Router ... Read more
Affected Products : next.js- Published: May. 30, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2009-3407
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-0983.... Read more
Affected Products : application_server- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025