Latest CVE Feed
-
4.3
MEDIUMCVE-2014-1472
Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : vulnerability_manager- Published: Jan. 16, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1441
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.... Read more
Affected Products : core_ftp- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-3844
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)... Read more
- Published: Apr. 17, 2024
- Modified: Dec. 19, 2024
-
4.3
MEDIUMCVE-2014-1369
WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to access file: URLs by leveraging a URL drag operation that originates at a crafted web site.... Read more
Affected Products : safari- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4687
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the starttime0 parameter to firewall_schedule.php, (2) the rssfeed parameter to rss.widget.php, (3) the servi... Read more
- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4692
pfSense before 2.1.4, when HTTP is used, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.... Read more
- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1564
Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field.... Read more
Affected Products : webgui- Published: Feb. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5248
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.... Read more
Affected Products : mybb- Published: Aug. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5851
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) prot... Read more
- Published: Nov. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0977
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0896
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.... Read more
Affected Products : websphere_application_server- Published: May. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6318
The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthor... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Published: Nov. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0611
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : groupwise- Published: Jul. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-17891
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical infor... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-17926
The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.... Read more
- Published: Jan. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-17859
An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.... Read more
Affected Products : joomla\!- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6340
Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Nov. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6345
Microsoft Internet Explorer 9 and 10 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Nov. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6350
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6349.... Read more
Affected Products : internet_explorer- Published: Nov. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-17857
An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation.... Read more
Affected Products : joomla\!- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024