Latest CVE Feed
-
4.3
MEDIUMCVE-2012-0313
Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2 allows remote attackers to inject arbitrary web script or HTML via an RSS feed.... Read more
Affected Products : glucose_2- Published: Jan. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-5256
Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is... Read more
- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4853
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-data/ite... Read more
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4710
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as... Read more
Affected Products : yui- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-16252
The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.... Read more
Affected Products : field_test- Published: Aug. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32148
Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1293
Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters.... Read more
Affected Products : fex- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-4874
The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.8 via the postId parameter due to missing validation on a user controlled key. This makes it possible for authenticated att... Read more
Affected Products : bricks- Published: Jun. 22, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4841
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to IND... Read more
- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3511
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_... Read more
Affected Products : image_gallery- Published: Aug. 07, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3894
Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header.... Read more
Affected Products : multifunctional_mailform_free- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3892
Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : meridian- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-2963
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) module_bbcodeloader.php, (2) module_div.php, (3) module_email... Read more
Affected Products : invision_power_board- Published: May. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-9361
The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly obtain sensitive information by acces... Read more
Affected Products : logintoboggan- Published: Dec. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1968
Cross-site scripting (XSS) vulnerability in the XooNIps module 3.47 and earlier for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : xoonips- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5016
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsact... Read more
Affected Products : limesurvey- Published: Jul. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3060
Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to (a) chat.php, (2) LANG[DEFAULT_BRANDING] and (3) PHPLIVE_VERSION parameters to (b) help.php, ... Read more
Affected Products : phplive- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-7047
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.... Read more
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8508
Cross-site scripting (XSS) vulnerability in s_network.asp in the Denon AVR-3313CI audio/video receiver allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to Friendlyname.... Read more
Affected Products : avr-3313ci- Published: Nov. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5716
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.... Read more
Affected Products : gom_player- Published: Sep. 09, 2013
- Modified: Apr. 11, 2025