Latest CVE Feed
-
4.3
MEDIUMCVE-2011-1592
The NFS dissector in epan/dissectors/packet-nfs.c in Wireshark 1.4.x before 1.4.5 on Windows uses an incorrect integer data type during decoding of SETCLIENTID calls, which allows remote attackers to cause a denial of service (application crash) via a cra... Read more
- Published: Apr. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1670
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit.... Read more
Affected Products : interra_blog_machine- Published: Apr. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2495
The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote at... Read more
- Published: Jun. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-20333
A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data within the interface on an affected device. This vulnerability is due to in... Read more
- Published: Mar. 27, 2024
- Modified: Jul. 23, 2025
-
4.3
MEDIUMCVE-2011-1582
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: t... Read more
Affected Products : tomcat- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-4467
The chmd_init_decomp function in chmd.c in libmspack before 0.5 does not properly validate the reset interval, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted CHM file.... Read more
- Published: Jun. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0323
Cross-site scripting (XSS) vulnerability in the Autocomplete plugin before 3.0 for SquirrelMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0309
Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0283
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.... Read more
Affected Products : dokuwiki- Published: Jul. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-1462
An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.... Read more
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-0390
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext vi... Read more
Affected Products : gnutls- Published: Jan. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0007
The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attack... Read more
Affected Products : anti-cross_site_scripting_library- Published: Jan. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0399
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : envision- Published: Mar. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5301
Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/... Read more
Affected Products : phpdug- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-3408
The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers ... Read more
Affected Products : bricks- Published: Aug. 17, 2024
- Modified: Sep. 13, 2024
-
4.3
MEDIUMCVE-2013-2081
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.... Read more
Affected Products : moodle- Published: May. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-41116
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardless o... Read more
Affected Products : postgres_advanced_server- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6249
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cau... Read more
- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6247
The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite lo... Read more
- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-0390
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.... Read more
Affected Products : gitlab- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024