Latest CVE Feed
-
4.3
MEDIUMCVE-2008-1204
Multiple cross-site scripting (XSS) vulnerabilities in the Administration Console in Sun Java System Access Manager 7.1 and 7 2005Q4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) Help and (2) Vers... Read more
Affected Products : java_system_access_manager- Published: Mar. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-27336
Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just Variables allows Cross Site Request Forgery. This issue affects Just Variables: from n/a through 1.2.3.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-27344
Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview allows Cross Site Request Forgery. This issue affects Phee's LinkPreview: from n/a through 1.6.7.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-52620
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2008-1202
Cross-site scripting (XSS) vulnerability in the web management interface in Adobe LiveCycle Workflow 6.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : livecycle_workflow- Published: Mar. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-27425
Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.... Read more
- Published: Mar. 04, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-27424
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.... Read more
- Published: Mar. 04, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2008-1355
Cross-site scripting (XSS) vulnerability in index.php in Jeebles Technology Jeebles Directory 2.9.60 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: the provenance of this information is unknown; the details a... Read more
Affected Products : jeebles_directory- Published: Mar. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-11821
A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enf... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1209
Cross-site scripting (XSS) vulnerability in redirect.do in Xitex WebContent M1 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from... Read more
Affected Products : xitex_webcontent_m1- Published: Mar. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-26532
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2019-19983
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call t... Read more
Affected Products : minify- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1073
Cross-site scripting (XSS) vulnerability in the report interface in Internet Security Systems (ISS) Internet Scanner 7.0 Service Pack 2 Build 7.2.2005.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : internet_scanner- Published: Feb. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-26849
There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain sensitive information such as firewall rules.... Read more
Affected Products : docusnap- Published: Mar. 04, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cryptography
-
4.3
MEDIUMCVE-2025-2527
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.... Read more
Affected Products : mattermost_server- Published: May. 15, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-26926
Cross-Site Request Forgery (CSRF) vulnerability in NotFound Booknetic. This issue affects Booknetic: from n/a through 4.0.9.... Read more
Affected Products : booknetic- Published: Feb. 25, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-26928
Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.... Read more
Affected Products :- Published: Feb. 25, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13368
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, an... Read more
Affected Products : youzify- Published: Jan. 25, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-27146
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed ... Read more
Affected Products : matrix_irc_bridge- Published: Feb. 25, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-8398
The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : simple_nav_archives- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery