Latest CVE Feed
-
4.3
MEDIUMCVE-2010-4453
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container.... Read more
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1564
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that ... Read more
- Published: Sep. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-4570
Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.... Read more
Affected Products : bugzilla- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2014
Cross-site scripting (XSS) vulnerability in cp/list_content.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the cl or possibly id parameter.... Read more
Affected Products : lisk_cms- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4388
The (1) Upsell.htm, (2) Main.html, and (3) Custsupport.html components in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allow remote attackers to inject code into the RealOneActiveXOb... Read more
- Published: Dec. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15060
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.... Read more
- Published: Aug. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4402
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) firstname, (2) lastname, (3) website, (4) aim, (5) ya... Read more
- Published: Dec. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4513
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter in a load action to zimplit.php and (2) client parameter to English_manu... Read more
Affected Products : zimplit_cms- Published: Dec. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13270
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.... Read more
Affected Products : freelinking- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-12826
The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend() function in all versions up to, and including, 3.5. This make... Read more
Affected Products : personalized_woocommerce_cart_page- Published: Jan. 25, 2025
- Modified: Jan. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2011-0455
Cross-site scripting (XSS) vulnerability in Things BBS before 2.0.3 and BBS Thread before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4515
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.... Read more
Affected Products : web_interface- Published: Dec. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-41313
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The ... Read more
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4522
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) editpost.php, (2) member.php, and (3) newreply.php.... Read more
Affected Products : mybb- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15003
OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).... Read more
Affected Products : open-xchange_appsuite- Published: Oct. 23, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4572
CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the query string... Read more
Affected Products : bugzilla- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of... Read more
- Published: Dec. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4407
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlGuest 1.1c-patched allow remote attackers to inject arbitrary web script or HTML via the (1) nome (nickname), (2) messaggio (message), and (3) link (homepage) parameters.... Read more
Affected Products : alguest- Published: Dec. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4405
Cross-site scripting (XSS) vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13783
The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level... Read more
Affected Products : formcraft- Published: Feb. 18, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Authorization