Latest CVE Feed
-
4.3
MEDIUMCVE-2022-20939
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to inadequate protection of sensitive ... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
4.3
MEDIUMCVE-2004-1648
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.... Read more
Affected Products : password_protect- Published: Aug. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4496
Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.... Read more
Affected Products : syntaxcms- Published: Dec. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4401
Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.... Read more
Affected Products : lutece- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4395
Cross-site scripting (XSS) vulnerability in FarCry 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the criteria parameter.... Read more
Affected Products : farcry- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-35913
Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow each other's paynym. Then, the victim must try to collaborate with the attacker for a Stonewallx2 transaction. Next, the attacker broad... Read more
Affected Products : samourai- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4375
Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.... Read more
Affected Products : amaxus- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4388
Cross-site scripting (XSS) vulnerability in search.cfm in CONTENS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the near parameter.... Read more
Affected Products : contens- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-15002
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2005-4322
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attacker... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4255
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.... Read more
Affected Products : wikkawiki- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4290
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.... Read more
Affected Products : ecw-cart- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-5276
The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."... Read more
- Published: Oct. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-4245
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.... Read more
Affected Products : snipe_gallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-6283
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the subject field of (1) a private message (PM) or (2) a bulletin board post.... Read more
Affected Products : vikingboard- Published: Dec. 04, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1774
Multiple cross-site scripting (XSS) vulnerabilities in aBitWhizzy allow remote attackers to inject arbitrary web script or HTML via the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php.... Read more
Affected Products : abitwhizzy- Published: Mar. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5599
Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE: it is likely that this issue overlaps one of t... Read more
Affected Products : apex- Published: Oct. 28, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4231
Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) link parameter to tell_friend.php, (2) phrase[] parameter to search.php in a search_links_advanced action, and ... Read more
Affected Products : link_up_gold- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1506
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using im... Read more
Affected Products : webcalendar- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-8103
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for u... Read more
Affected Products : wpematico_rss_feed_fetcher- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Request Forgery