Latest CVE Feed
-
4.3
MEDIUMCVE-2023-2632
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.... Read more
Affected Products : code_dx- Published: May. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1494
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.... Read more
Affected Products : megabook- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2241
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the ven... Read more
Affected Products : phorum- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-2791
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post. ... Read more
- Published: Jun. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2294
Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous s... Read more
Affected Products : php-nuke- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-3771
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-1861
An issue existed in determining cache occupancy. The issue was addressed through improved logic. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to track users by setting state in a cache.... Read more
Affected Products : macos- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2901
Multiple Cross-site scripting (XSS) vulnerabilities in CjWeb2Mail 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message, or (3) ip parameter to thankyou.php or (4) emsg parameter to web2mail.php.... Read more
Affected Products : cjweb2mail- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1557
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.... Read more
Affected Products : guestbook_pro- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1945
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.... Read more
Affected Products : invision_community_blog- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1320
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : mnemo- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-2714
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_license' functions in versions up to, and including, 2.7.9.8. This makes it possible for authenticated attackers, with s... Read more
Affected Products : groundhogg- Published: May. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21523
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with netwo... Read more
Affected Products : bi_publisher- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-5963
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax opera... Read more
Affected Products : gitlab- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2254
Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there... Read more
Affected Products : phpauction- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0818
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.... Read more
Affected Products : punbb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4821
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal_userreview_module- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-1451
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : sma-db- Published: Apr. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-39327
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.... Read more
- Published: Jul. 13, 2024
- Modified: Aug. 08, 2025
-
4.3
MEDIUMCVE-2023-29178
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd proc... Read more
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024