Latest CVE Feed
-
4.3
MEDIUMCVE-2007-1509
Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter.... Read more
Affected Products : rot_13- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-9721
libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.... Read more
- Published: Jun. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-0649
Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the sr... Read more
- Published: Feb. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1977
Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.... Read more
Affected Products : holacms- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5932
Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and po... Read more
Affected Products : fatwire_content_server- Published: Nov. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1462
The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view ... Read more
- Published: Mar. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1418
Cross-site scripting (XSS) vulnerability in skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before Gooseberry++ allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : dekiwiki- Published: Mar. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-40338
Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins contr... Read more
Affected Products : folders- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6300
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.... Read more
Affected Products : cutenews- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-28557
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to leak sens... Read more
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1361
Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart before 20070213 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue is probably different than CVE-2007-0376.... Read more
Affected Products : virtuemart- Published: Mar. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-46442
An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).... Read more
Affected Products :- Published: May. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1362
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within... Read more
- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1965
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.... Read more
Affected Products : content_management_system- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-39870
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0298
Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.... Read more
Affected Products : mod_cluster- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-1114
The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, a... Read more
- Published: Feb. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1049
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the... Read more
- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6832
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.... Read more
Affected Products : joomla- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-4221
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*... Read more
- Published: Dec. 22, 2022
- Modified: Apr. 16, 2025