Latest CVE Feed
-
4.3
MEDIUMCVE-2015-7373
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.... Read more
Affected Products : revive_adserver- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3016
Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a j... Read more
Affected Products : safari- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.... Read more
Affected Products : yith_woocommerce_wishlist yith_woocommerce_compare yith_woocommerce_quick_view yith_woocommerce_zoom_magnifier yith_woocommerce_ajax_search yith_woocommerce_badge_management yith_woocommerce_brands_add-on yith_woocommerce_request_a_quote yith_woocommerce_social_login yith_woocommerce_order_tracking +28 more products- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-7181
Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the maxbuttons-controller page to wp-admin/... Read more
Affected Products : maxbuttons- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4973
Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : b2b_advanced_communications- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-1969
Cross-site scripting (XSS) vulnerability in HP Virtual Connect Enterprise Manager for Windows before 6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
- Published: Jul. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0912
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2715
Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.... Read more
Affected Products : tcw_php_album- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-5651
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dotclear- Published: Oct. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-2718
Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware CruxPA 2.00, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) txtusername parameter to login.php, (2) todo parameter to newtodo.php, and uns... Read more
Affected Products : cruxpa- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5845
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Administration.... Read more
Affected Products : ilearning- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3155
Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.... Read more
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-11808
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretic... Read more
Affected Products : ratpack- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2464
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.... Read more
- Published: Jun. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5388
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK5F.... Read more
Affected Products : lotus_domino- Published: Oct. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2442
Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."... Read more
Affected Products : internet_explorer- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6280
Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action or (2) nsextt parameter to oc-admin/index.php or the (3) nsextt parameter in an items_reported act... Read more
Affected Products : osclass- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6281
Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "page" parameter.... Read more
Affected Products : dhtmlxspreadsheet- Published: Oct. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4447
Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.... Read more
Affected Products : simplenews- Published: Nov. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2355
Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained sol... Read more
Affected Products : elms_pro- Published: Jun. 21, 2010
- Modified: Apr. 11, 2025