Latest CVE Feed
-
4.3
MEDIUMCVE-2008-4876
Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly ha... Read more
Affected Products : voip841_dect_phone- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6400
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) search.php. NOTE: some of these details are obtained from third party info... Read more
Affected Products : refbase- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-0358
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-5059
Cross-site scripting (XSS) vulnerability in index.php in ModernBill 4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript event in the new_language parameter in a login action.... Read more
Affected Products : modernbill- Published: Nov. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3348
Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.... Read more
Affected Products : gyro- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-0268
XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before ... Read more
Affected Products : financial_transaction_manager- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-4004
Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allows remote attackers to inject arbitrary web script or HTML via a crafted applicat... Read more
Affected Products : sleipnir_mobile- Published: Aug. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5799
Cross-site scripting (XSS) vulnerability in the Wir ber uns (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4226
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string t... Read more
Affected Products : quick_post_widget- Published: Sep. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4236
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : ecommerce- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-12973
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.... Read more
Affected Products : nimbus_jose\+jwt- Published: Aug. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2005-4580
Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.... Read more
Affected Products : communique- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-6063
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Tempo... Read more
Affected Products : word- Published: Feb. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-8653
Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to inject arbitrary web script or HTML via the userData cookie.... Read more
- Published: Nov. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-6238
Cross-site scripting (XSS) vulnerability in archive/savedqueries/savequeryfinish.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the name parameter.... Read more
Affected Products : openedit_digital_asset_management- Published: Feb. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2997
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action.... Read more
Affected Products : gravity_board_x- Published: Jul. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6340
Cross-site scripting (XSS) vulnerability in the Vox populi (mv_vox_populi) extension 0.3.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-7452
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive informatio... Read more
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.... Read more
- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4909
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025