Latest CVE Feed
-
4.3
MEDIUMCVE-2012-4336
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.... Read more
Affected Products : flogr- Published: Sep. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-42501
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` t... Read more
Affected Products : superset- Published: Nov. 27, 2023
- Modified: Feb. 13, 2025
-
4.3
MEDIUMCVE-2008-5961
Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to inject arbitrary web script or HTML via the cID parameter in a document action. NOTE: the provenance of this information is unkno... Read more
Affected Products : tribiq_cms- Published: Jan. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4485
Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a nod... Read more
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4609
The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : rsa_netwitness_informer- Published: Dec. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4460
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.... Read more
Affected Products : auto-surf_traffic_exchange_script- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4516
Cross-site scripting (XSS) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5416
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_delete_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, ... Read more
- Published: Nov. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0204
Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fi... Read more
Affected Products : wordcircle- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-4548
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5... Read more
Affected Products : viart_helpdesk- Published: Jan. 04, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5387
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_trigger_dark_mode function in versions up to, and including, 3.4. This makes it possible for authenticated attac... Read more
- Published: Nov. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-4968
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary,... Read more
- Published: Sep. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-41146
Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account. ... Read more
Affected Products : customer_portal- Published: Nov. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5058
Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to the Web interface.... Read more
Affected Products : e-business_suite- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-22151
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.... Read more
Affected Products : kibana- Published: Nov. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4688
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.... Read more
Affected Products : php_shopping_cart_selling_website_script- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4746
Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.... Read more
Affected Products : dreampoll- Published: Mar. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1339
Cross-site scripting (XSS) vulnerability in Google Search Appliance before 5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : search_appliance- Published: Jul. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-30862
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.22.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-5182
The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive information about logged locations via a crafted application.... Read more
Affected Products : loctouch- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025