Latest CVE Feed
-
4.3
MEDIUMCVE-2007-1199
Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file:///C:/)/S/URI>>, a different issue than CVE-2007-0045.... Read more
Affected Products : acrobat_reader- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0478
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certa... Read more
- Published: Jan. 25, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1159
Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely fr... Read more
Affected Products : pyrophobia- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1004
Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.... Read more
Affected Products : firefox- Published: Feb. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1231
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php an... Read more
Affected Products : sqlitemanager- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-2303
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the ... Read more
Affected Products : gitlab- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22935
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.... Read more
Affected Products : salt- Published: Mar. 29, 2022
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2023-4629
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the 'ladipage_con... Read more
Affected Products : ladipage- Published: Mar. 12, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2006-6729
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : a-blog- Published: Dec. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-22924
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved ... Read more
- Published: Aug. 05, 2021
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2007-0982
Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter. NOTE: the provenance of this information is unknown; the details are obtained solely fr... Read more
Affected Products : taskfreak- Published: Feb. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-3444
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)... Read more
Affected Products : chrome- Published: Nov. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0925
Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : community_server- Published: Feb. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1238
Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.... Read more
Affected Products : office- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0817
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.... Read more
Affected Products : coldfusion- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1965
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.... Read more
Affected Products : content_management_system- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6126
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is rea... Read more
Affected Products : project_alumni- Published: Nov. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1623
Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) f... Read more
Affected Products : realguestbook- Published: Mar. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-48653
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.... Read more
- Published: Feb. 29, 2024
- Modified: Dec. 16, 2024
-
4.3
MEDIUMCVE-2023-46171
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: 269408.... Read more
- Published: Mar. 07, 2024
- Modified: Mar. 11, 2025