Latest CVE Feed
-
4.3
MEDIUMCVE-2006-1696
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : gallery- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-1497
Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : dl_stats- Published: Apr. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1486
Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.... Read more
Affected Products : cactushop- Published: Apr. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-9993
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0398
IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.... Read more
Affected Products : cognos_analytics- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-42026
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio Pro do not properly control read ac... Read more
Affected Products : mendix- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3037
Cross-site scripting (XSS) vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : address_directory- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-0192
The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker t... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2020-14183
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected ve... Read more
- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-0069
Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0033.... Read more
Affected Products : edge- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2024-43813
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2016-8923
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.... Read more
Affected Products : curam_social_program_management- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-1071
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised u... Read more
Affected Products : gitlab- Published: Apr. 05, 2023
- Modified: Feb. 10, 2025
-
4.3
MEDIUMCVE-2019-13754
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.... Read more
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-13717
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47554
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 ... Read more
- Published: Oct. 03, 2024
- Modified: Jul. 10, 2025
-
4.3
MEDIUMCVE-2020-14578
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight oncommand_workflow_automation jdk jre +11 more products- Published: Jul. 15, 2020
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2024-43105
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2022-27199
A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.... Read more
Affected Products : cloudbees_aws_credentials- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-26383
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.... Read more
- Published: Dec. 22, 2022
- Modified: Apr. 16, 2025