Latest CVE Feed
-
4.3
MEDIUMCVE-2019-5465
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.... Read more
Affected Products : gitlab- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-19004
LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration.... Read more
Affected Products : laquis_scada- Published: Feb. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0724
Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12 in Cisco Headend Digital Broadband Delivery System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID C... Read more
Affected Products : headend_digital_broadband_delivery_system- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0734
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCut87743.... Read more
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6296
Cross-site scripting (XSS) vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wec_map- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2250
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel pa... Read more
Affected Products : concrete5- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-0278
Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database tables used by the application, lead... Read more
Affected Products : netweaver_process_integration- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-3833
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.... Read more
Affected Products : safari- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-12846
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.... Read more
Affected Products : teamcity- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-14180
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-ty... Read more
Affected Products : jira_service_desk- Published: Sep. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-3300
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1)... Read more
Affected Products : thecartpress_ecommerce_shopping_cart- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1224
Incomplete blacklist vulnerability in the user registration feature in rexx Recruitment R6.1 and R7 without "fixes from 2014-01-15" allows remote attackers to conduct cross-site scripting (XSS) attacks via the oninput event handler in the fname parameter ... Read more
Affected Products : recruitment- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4871
Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject arbitrary web script or HTML via the wlWpaPsk parameter.... Read more
- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3397
Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7.... Read more
- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-2700
Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network ac... Read more
- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-7857
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.... Read more
Affected Products : magento- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10342
A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : docker- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10806
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.... Read more
Affected Products : vega- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9386
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.... Read more
Affected Products : mahara- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2147
A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.... Read more
Affected Products : mac- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024