Latest CVE Feed
-
4.3
MEDIUMCVE-2008-6838
Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to inject arbitrary web script or HTML via the _off parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third ... Read more
Affected Products : zoph- Published: Jun. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-41413
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.... Read more
Affected Products : perfsonar- Published: Nov. 30, 2022
- Modified: May. 02, 2025
-
4.3
MEDIUMCVE-2019-15871
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.... Read more
Affected Products : loginpress- Published: Sep. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2373
Unspecified vulnerability in the Console component in Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5 allows remote attackers to affect integrity via unknown vectors.... Read more
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-4830
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this coo... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2889
Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.... Read more
Affected Products : hangman- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6624
System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23999740.... Read more
Affected Products : android- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-28834
Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, as well as Nextcloud Enterprise Server 23.0.0 until 23.0.11, 24.0.0 until 24.0.6, and 25.0.0 until 25.0.4, have an information disclosu... Read more
- Published: Apr. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0515
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.... Read more
Affected Products : crater- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3918
Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the node title.... Read more
- Published: Nov. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2004-2465
Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : easy_chat_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-4845
Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bannerman_background parameter to wp-admin/options-general.php.... Read more
Affected Products : bannerman- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-23586
A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
4.3
MEDIUMCVE-2016-3517
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect integrity via vectors related to PC / Get Shortcut.... Read more
- Published: Jul. 21, 2016
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2011-3689
Cross-site scripting (XSS) vulnerability in Licenses.html in Wibu-Systems CodeMeter WebAdmin 3.30 and 4.30 allows remote attackers to inject arbitrary web script or HTML via the BoxSerial parameter.... Read more
Affected Products : codemeter_webadmin- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-1594
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL... Read more
Affected Products : hc_custom_wp-admin_url- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2094
A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.... Read more
Affected Products : health_advisor_by_cloudbees- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-47130
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.... Read more
Affected Products : academy_lms- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
4.3
MEDIUMCVE-2021-41176
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's s... Read more
Affected Products : panel- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-14403
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024