Latest CVE Feed
-
4.3
MEDIUMCVE-2016-1501
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.... Read more
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-1470
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.... Read more
Affected Products : sterling_file_gateway- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3342
Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.... Read more
Affected Products : easypublish- Published: Jul. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7080
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.... Read more
Affected Products : content_management_system- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-27907
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.... Read more
Affected Products : nexus_repository_manager- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-11658
Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access... Read more
Affected Products : content_manager- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-8972
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.... Read more
Affected Products : matrix_operating_environment- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6978
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.... Read more
- Published: Feb. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1564
Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the filename.... Read more
Affected Products : file_transfer- Published: Mar. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1881
Cross-site scripting (XSS) vulnerability in MT312 IMG-BBS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to model.php with a timestamp before 20090521.... Read more
Affected Products : img-bbs- Published: Jun. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1877
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.... Read more
Affected Products : coldfusion- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6090
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.... Read more
Affected Products : mini_hosting_panel- Published: Feb. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-11273
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be a... Read more
Affected Products : pivotal_container_service- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-1320
Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtain... Read more
Affected Products : store_builder- Published: Apr. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-5490
Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : plone- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-34313
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent... Read more
Affected Products : cics_tx- Published: Nov. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1449
Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.... Read more
Affected Products : php-nuke- Published: Mar. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-25950
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.... Read more
Affected Products : advanced_webhost_billing_system- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2057
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 6.0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-2174
The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers,... Read more
Affected Products : badgeos- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024