Latest CVE Feed
-
4.3
MEDIUMCVE-2006-0676
Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter.... Read more
Affected Products : php-nuke- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0682
Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : e107- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2123
Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and po... Read more
Affected Products : e-commerce_asp_engine- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-4899
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.ph... Read more
Affected Products : boinc_forum- Published: Sep. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4348
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entrie... Read more
Affected Products : tivoli_storage_manager_client- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4813
Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third p... Read more
Affected Products : domino_blogsphere- Published: Sep. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1242
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : webi- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-4975
Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.... Read more
Affected Products : b1gmail- Published: Sep. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5059
Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL allow remote attackers to inject arbitrary web script or HTML via several vectors, as demonstrated by the (1) uname and (2) pass parameters in a login form, and (3) an unspecified "url value,... Read more
Affected Products : greensql- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7238
Cross-site scripting (XSS) vulnerability in MyShoutPro before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : myshoutpro- Published: Apr. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1276
Multiple cross-site scripting (XSS) vulnerabilities in BBSXP 2008 SP2 allow remote attackers to inject arbitrary web script or HTML via the URI in a request to (1) AddPost.asp, (2) AddTopic.asp, (3) Admin_Default.asp, (4) Bank.asp, (5) Manage.asp, and (6)... Read more
Affected Products : bbsxp- Published: Apr. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3202
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark.... Read more
Affected Products : flock- Published: Sep. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-1599
Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field.... Read more
Affected Products : subject_search_server- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-1515
IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825.... Read more
- Published: Jan. 26, 2018
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2017-12287
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected s... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-30510
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a sub... Read more
Affected Products : edgeconnect_enterprise- Published: May. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1652
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated at... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2023-3201
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_new_order_title function. This makes it possible for unauthenticated attackers to update new order title via a forged requ... Read more
Affected Products : mstore_api- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4004
The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use ... Read more
Affected Products : donation_button- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
4.3
MEDIUMCVE-2023-23616
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the re... Read more
Affected Products : discourse- Published: Jan. 28, 2023
- Modified: Nov. 21, 2024