Latest CVE Feed
-
4.3
MEDIUMCVE-2004-1735
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : sympa- Published: Aug. 21, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-26412
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.... Read more
Affected Products : gitlab- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1341
Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.... Read more
Affected Products : info2www- Published: Apr. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2492
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.... Read more
Affected Products : groupmax_world_wide_web_desktop- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1237
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.... Read more
Affected Products : wwwboard- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1999
Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.... Read more
Affected Products : php-nuke- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-2902
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Console). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
Affected Products : weblogic_server- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-3329
A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an ... Read more
Affected Products : integrated_management_controller_supervisor ucs_director ucs_director_express_for_big_data- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41864
Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF7 Database: from n/a through 1.8.0. ... Read more
Affected Products : peprodev_cf7_database- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-30450
rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turne... Read more
Affected Products : redpanda- Published: Apr. 08, 2023
- Modified: Feb. 12, 2025
-
4.3
MEDIUMCVE-2023-30480
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5. ... Read more
Affected Products :- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2512
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.... Read more
Affected Products : dcp-portal- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-41865
Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2023-30530
Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products : consul_kv_builder- Published: Apr. 12, 2023
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2004-2188
Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis Manager allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : dmxready_site_chassis_manager- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-30534
Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets a... Read more
- Published: Sep. 05, 2023
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-29111
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confi... Read more
Affected Products : application_interface_framework- Published: Apr. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41723
A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot ... Read more
Affected Products : one- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1397
Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl.... Read more
Affected Products : usemodwiki- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-11803
Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Discl... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025