Latest CVE Feed
-
4.3
MEDIUMCVE-2012-1103
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the me... Read more
- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-32790
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-40264
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.... Read more
Affected Products : openscape_voice_trace_manager_v8- Published: Feb. 08, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2024-22339
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from so... Read more
- Published: Apr. 12, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2023-40292
Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.... Read more
Affected Products : harman_infotainment- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1395
Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter.... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6646
Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : phpaddressbook- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6692
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is n... Read more
- Published: Jun. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3359
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.... Read more
Affected Products : match_agency_biz- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-0989
Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.... Read more
Affected Products : action_and_information_management_system- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6495
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter.... Read more
Affected Products : yappa-ng- Published: Mar. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6173
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : clipshare- Published: Feb. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0369
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.... Read more
Affected Products : internet_explorer- Published: Jan. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4246
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter; or the (2) footer, (3) status, or (4) testtarget parameter in ... Read more
Affected Products : phplist- Published: Aug. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-47705
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.... Read more
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4942
Multiple cross-site scripting (XSS) vulnerabilities in admin/configuration.php in Geeklog before 1.7.1sr1 allow remote attackers to inject arbitrary web script or HTML via the (1) subgroup or (2) conf_group parameters. NOTE: this vulnerability might requ... Read more
Affected Products : geeklog- Published: Sep. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-25336
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.... Read more
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-0820
Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0822.... Read more
Affected Products : joomla\!- Published: Sep. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-4426
The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the metabox_review_save() function. This makes it possible for unauthent... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4571
Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter.... Read more
Affected Products : vn-calendar- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025