Latest CVE Feed
-
4.3
MEDIUMCVE-2015-1373
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not properl... Read more
Affected Products : ferretcms- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6462
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors related to Admin Console.... Read more
Affected Products : fusion_middleware- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0810
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript ... Read more
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-40630
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected vers... Read more
Affected Products : openimageio- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0456
Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Portlet Services.... Read more
Affected Products : fusion_middleware- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5094
Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.... Read more
Affected Products : vulnerability_manager- Published: Jan. 28, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6445
Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.... Read more
Affected Products : contact_form_7_integrations- Published: Sep. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9349
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php.... Read more
Affected Products : robotstats- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-1854
A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .... Read more
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1248
The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: U... Read more
- Published: Apr. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-36747
The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the metabox_save() function. This makes it possible for unaut... Read more
Affected Products : lightweight_sidebar_manager- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3635
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted ali... Read more
Affected Products : empathy- Published: Oct. 23, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-2080
The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.76 via the poller_list shortcode. This makes it possible for authenticated attackers, ... Read more
Affected Products :- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4544
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager rational_rhapsody_design_manager rational_team_concert rhapsody_model_manager collaborative_lifecycle_management doors_next engineering_insights +5 more products- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5234
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.... Read more
Affected Products : open-xchange_appsuite- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8150
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.... Read more
- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8091
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to caus... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
4.3
MEDIUMCVE-2020-36749
The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthentic... Read more
Affected Products : easy_testimonials- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4231
Unspecified vulnerability in the Siebel Travel & Transportation component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Diary.... Read more
Affected Products : siebel_crm- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9281
Cross-site scripting (XSS) vulnerability in admin/copy_field.php in MantisBT before 1.2.18 allows remote attackers to inject arbitrary web script or HTML via the dest_id field.... Read more
Affected Products : mantisbt- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025