Latest CVE Feed
-
4.3
MEDIUMCVE-2008-4532
Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.... Read more
Affected Products : website_directory- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4481
Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : redmine- Published: Oct. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3919
Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."... Read more
- Published: Nov. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-10022
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privi... Read more
Affected Products : flexcube_private_banking- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-4432
Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.... Read more
- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2896
Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1916
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text fields intended for the (1) address and (2) order information, which are la... Read more
- Published: Apr. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-1000243
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites... Read more
Affected Products : favorite_plugin- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-3105
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 211.241 for Domino 8.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR EZEL7UURYC.... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1956
Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter.... Read more
Affected Products : opus- Published: Apr. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-0388
Unspecified vulnerability in the PeopleSoft HRMS component in Oracle PeopleSoft Products 9.1 allows remote attackers to affect integrity via unknown vectors related to Mobile Company Directory.... Read more
Affected Products : peoplesoft_products- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10323
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : artifactory- Published: May. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1716
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : xymon- Published: Apr. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-3000
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7268
Cross-site scripting (XSS) vulnerability in the data-export feature in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CV... Read more
Affected Products : wbs_gantt-chart- Published: Dec. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-2638
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchR... Read more
Affected Products : phpfreenews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-3162
Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.... Read more
Affected Products : multi_website- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2003-0623
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-4841
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.... Read more
Affected Products : mailwise- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2005-4400
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.... Read more
Affected Products : liferay_portal_enterprise- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025