Latest CVE Feed
-
4.3
MEDIUMCVE-2007-3669
Multiple unspecified vulnerabilities in the Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control have unspecified attack vectors and impact, including a denial of service via "improper use" of the SaveToFile function.... Read more
Affected Products : dockstudioxp- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4365
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog via the add_blog action, (2) approve a comment via the ... Read more
Affected Products : ez_blog- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0923
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.... Read more
Affected Products : myphpnuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-6565
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.... Read more
Affected Products : invision_power_board- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-26595
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site mem... Read more
- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2288
Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to inject arbitrary web script or HTML via the DSSignInURL cookie.... Read more
Affected Products : secure_access- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-1975
Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters... Read more
Affected Products : 1two- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-4292
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818.... Read more
- Published: Aug. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2181
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbasedir parameter.... Read more
Affected Products : campsite- Published: Jun. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2968
Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field).... Read more
Affected Products : cpcommerce- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2167
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.... Read more
Affected Products : plague_news_system- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-22479
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit ... Read more
Affected Products : storage_manager- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-22779
Missing Authorization vulnerability in Ugur CELIK WP News Sliders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP News Sliders: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22215
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.... Read more
Affected Products : aria_automation- Published: Jan. 08, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Server-Side Request Forgery
-
4.3
MEDIUMCVE-2025-22561
Missing Authorization vulnerability in Jason Funk Title Experiments Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Title Experiments Free: from n/a through 9.0.4.... Read more
Affected Products : title_experiments_free- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24696
Cross-Site Request Forgery (CSRF) vulnerability in WP Attire Attire Blocks allows Cross Site Request Forgery. This issue affects Attire Blocks: from n/a through 1.9.6.... Read more
Affected Products : attire_blocks- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-22721
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline – Application Form Builder and Manager: from n/a ... Read more
Affected Products : applyonline_-_application_form_builder_and_manager- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24693
Missing Authorization vulnerability in Yehi Advanced Notifications allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Notifications: from n/a through 1.2.7.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-23684
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Debug Tool: from n/a through 2.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-23423
Missing Authorization vulnerability in Smackcoders SendGrid for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendGrid for WordPress: from n/a through 1.4.... Read more
Affected Products : sendgrid- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authorization