Latest CVE Feed
-
4.3
MEDIUMCVE-2008-3421
Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) upda... Read more
Affected Products : blackboard_academic_suite- Published: Jul. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1445
The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abi field. NOTE: this may later be SPLIT i... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3482
Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspec... Read more
- Published: Aug. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2508
Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.... Read more
Affected Products : tr_script_news- Published: May. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0437
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a... Read more
- Published: Feb. 06, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2494
Cross-site scripting (XSS) vulnerability in index.php in Zina 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via the l parameter.... Read more
Affected Products : zina- Published: May. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2449
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to imag... Read more
Affected Products : phpinstantgallery- Published: May. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0136
Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these deta... Read more
Affected Products : drupal- Published: Jan. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-8891
The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attacker... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2020-10715
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convi... Read more
Affected Products : openshift- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0857
Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.... Read more
- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-3483
Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page.... Read more
Affected Products : screwturn_wiki- Published: Aug. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3569
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php.... Read more
- Published: Aug. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3581
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.... Read more
Affected Products : k-links- Published: Aug. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1707
IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a packet with an 0x11 value in a certain "type" field.... Read more
Affected Products : soliddb- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-2874
Google Chrome before 28.0.1500.71 on Windows, when an Nvidia GPU is used, allows remote attackers to bypass intended restrictions on access to screen data via vectors involving IPC transmission of GL textures.... Read more
- Published: Jul. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3510
Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.... Read more
Affected Products : crafty_syntax_live_help- Published: Aug. 07, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3708
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.... Read more
Affected Products : dotcms- Published: Aug. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3860
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotu... Read more
- Published: Aug. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1708
IBM solidDB 06.00.1018 and earlier does not validate a certain field that specifies an amount of memory to allocate, which allows remote attackers to cause a denial of service (daemon exit) via a packet with a large value in this field.... Read more
Affected Products : soliddb- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025