Latest CVE Feed
-
4.3
MEDIUMCVE-2007-3274
Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.... Read more
- Published: Jun. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2925
Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to a... Read more
- Published: Apr. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0915
Cross-site scripting (XSS) vulnerability in RAKUS MailDealer 11.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted attachment filename.... Read more
Affected Products : maildealer- Published: May. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-21320
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin t... Read more
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-5066
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine randomly ... Read more
Affected Products : virtual_war- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-50923
In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which might allow remote attackers to construct a covert channel with data represented as changes to the bit val... Read more
Affected Products :- Published: Feb. 21, 2024
- Modified: Dec. 04, 2024
-
4.3
MEDIUMCVE-2012-0566
Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 5.2.2, 6.0.0, and 6.1.1 allows remote attackers to affect integrity via unknown vectors related to Supplier Portal.... Read more
Affected Products : supply_chain_products_suite- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3444
The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags.... Read more
Affected Products : firefox- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6341
Cross-site scripting (XSS) vulnerability in the SB Universal Plugin (SBuniplug) extension 2.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-52711
Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a thro... Read more
Affected Products : post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2015-0871
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : guestbook- Published: Feb. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-5010
Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.... Read more
Affected Products : schoolmation- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3948
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : inp- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-1846
The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : tiny_contact_form- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3036
Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors.... Read more
Affected Products : api_management- Published: Jun. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0404
Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : documentum_eroom- Published: Mar. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-32790
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-4283
Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter.... Read more
- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3584
Cross-site scripting (XSS) vulnerability in Corporater EPM Suite allows remote attackers to inject arbitrary web script or HTML via the customerId parameter to an unspecified component.... Read more
Affected Products : epm_suite- Published: Aug. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3541
Cross-site scripting (XSS) vulnerability in Kurinton sHTTPd 20070408 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : shttpd- Published: Jul. 03, 2007
- Modified: Apr. 09, 2025