Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3971
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.... Read more
- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4053
Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html.... Read more
Affected Products : cowiki- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0194
Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.... Read more
Affected Products : fogbugz- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2088
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Enc... Read more
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-36050
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.... Read more
Affected Products :- Published: May. 18, 2024
- Modified: Jun. 27, 2025
-
4.3
MEDIUMCVE-2023-33946
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a differen... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-54004
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.... Read more
Affected Products : filesystem_list_parameter- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
4.3
MEDIUMCVE-2005-3436
Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows remote attackers to inject arbitrary web script or HTML via the (1) Search module, (2) certain edit fields in Guestbook, (3) the title in the Forum module, and (4) Textbox.... Read more
Affected Products : nuked-klan- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-24427
Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An... Read more
- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4024
Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : fastfind- Published: Dec. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3403
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) th... Read more
Affected Products : atutor- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-34779
A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : xebialabs_xl_release- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4022
Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.... Read more
Affected Products : gallery- Published: Dec. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-34047
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOpti... Read more
Affected Products : spring_for_graphql- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3908
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.... Read more
Affected Products : amazon_shop- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0073
Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error... Read more
- Published: Jan. 04, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-22890
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the... Read more
Affected Products : fedora debian_linux curl fabric_operating_system hci_management_node solidfire libcurl sinec_infrastructure_network_services hci_storage_node communications_billing_and_revenue_management +2 more products- Published: Apr. 01, 2021
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2005-3025
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.p... Read more
Affected Products : vbulletin- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0156
Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.... Read more
Affected Products : foxrum- Published: Jan. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-24374
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.... Read more
Affected Products : twig- Published: Jan. 29, 2025
- Modified: Jan. 29, 2025
- Vuln Type: Cross-Site Scripting