Latest CVE Feed
-
4.3
MEDIUMCVE-2022-36953
In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.... Read more
Affected Products : netbackup- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6625
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2020-4015
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.... Read more
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-17143
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : phantompdf- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37532
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.... Read more
Affected Products : business_one- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-7098
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3) the gallery, possibly the Description field in Your Pic... Read more
Affected Products : k-rate- Published: Aug. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-4569
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.... Read more
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3334
Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.... Read more
Affected Products : mybb- Published: Jul. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-27040
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.... Read more
Affected Products : autocad advance_steel autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d civil_3d +3 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0199
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack... Read more
Affected Products : coming_soon_and_maintenance_mode- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1564
Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : yvs_image_gallery- Published: Oct. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-0504
The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack... Read more
Affected Products : ht_politic- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
4.3
MEDIUMCVE-2010-5064
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script or HTML via (1) the Additional Information field to challenge.php, the (2) Additional Information or (3) Contact i... Read more
Affected Products : virtual_war- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0357
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.... Read more
- Published: Jul. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-7019
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. ... Read more
Affected Products : lightstart- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025
-
4.3
MEDIUMCVE-2024-38313
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.... Read more
Affected Products : firefox- Published: Jun. 13, 2024
- Modified: Mar. 14, 2025
-
4.3
MEDIUMCVE-2005-2327
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.... Read more
Affected Products : e107- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-23266
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.... Read more
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0471
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect confidentiality via unknown vectors related to Multichannel Framework.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-50900
Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.... Read more
Affected Products : master_slider- Published: Jun. 19, 2024
- Modified: May. 27, 2025