Latest CVE Feed
-
4.3
MEDIUMCVE-2010-1367
Multiple cross-site scripting (XSS) vulnerabilities in admin/admin_login.php in Uiga Fan Club, as downloaded on 20100310, allow remote attackers to inject arbitrary web script or HTML via the (1) admin_name and (2) admin_password parameters. NOTE: the pr... Read more
Affected Products : fan_club- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-14579
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight oncommand_workflow_automation jdk jre +11 more products- Published: Jul. 15, 2020
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2010-2636
Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_commerce- Published: Nov. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-43433
Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : screenrecorder- Published: Oct. 19, 2022
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2010-2658
Opera before 10.60 does not properly restrict certain interaction between plug-ins, file inputs, and the clipboard, which allows user-assisted remote attackers to trigger the uploading of arbitrary files via a crafted web site.... Read more
Affected Products : opera_browser- Published: Jul. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2103
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, a... Read more
- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0940
Cross-site scripting (XSS) vulnerability in guestbook.php in Simple PHP Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : simple_php_guestbook- Published: Mar. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2654
Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via t... Read more
- Published: Jul. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2414
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a ... Read more
- Published: Aug. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-14684
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability all... Read more
Affected Products : financial_services_analytical_applications_infrastructure- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0936
Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname parameter.... Read more
Affected Products : dkvm-ip8- Published: Mar. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2663
Opera before 10.60 allows remote attackers to cause a denial of service (application hang) via an ended event handler that changes the SRC attribute of an AUDIO element.... Read more
Affected Products : opera_browser- Published: Jul. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2671
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.... Read more
Affected Products : ez_publish- Published: Jul. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0582
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business ... Read more
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0949
Multiple cross-site scripting (XSS) vulnerabilities in Natychmiast CMS allow remote attackers to inject arbitrary web script or HTML via the id_str parameter to (1) index.php and (2) a_index.php.... Read more
Affected Products : natychmiast-cms- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0920
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer ... Read more
- Published: Mar. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-0822
The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.... Read more
- Published: Feb. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-11741
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, ... Read more
Affected Products : grafana- Published: Jan. 31, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2010-0927
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage a... Read more
Affected Products : lotus_domino- Published: Mar. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1764
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, follows multiple redirections during form submission, which allows remote web servers to obtain sensitive information by recording the form data.... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025