Latest CVE Feed
-
4.3
MEDIUMCVE-2023-5477
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)... Read more
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1986
Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.... Read more
Affected Products : pixel_motion_blog- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0122
Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.... Read more
Affected Products : aquifer_cms- Published: Jan. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1980
Cross-site scripting (XSS) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2046
Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter.... Read more
Affected Products : sitexs_cms- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2000
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.... Read more
Affected Products : safari- Published: Apr. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1987
Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : encapsgallery- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-48318
Cross-Site Request Forgery (CSRF) vulnerability in shen2 多说社会化评论框 allows Cross Site Request Forgery. This issue affects 多说社会化评论框: from n/a through 1.2.... Read more
Affected Products :- Published: Aug. 28, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-2006
Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit i... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2026
Cross-site scripting (XSS) vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258, and other versions before 5.3.3.378, allows remote attackers to inject arbitrary web script or HTML via a URL-encoded postdata parameter. NOTE: thi... Read more
Affected Products : authentication_agent- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2024
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.... Read more
Affected Products : minibb- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2009
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree fun... Read more
- Published: May. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4187
Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.... Read more
Affected Products : proactive_cms- Published: Sep. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-3284
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3. This is due to missing or incorrect nonce validation ... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-1327
The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.4 via the 'homey_delete_user_account' action due to missing validation on a user controlled key. This makes it possible for authentic... Read more
Affected Products : homey- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-1326
The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the homey_reservation_del() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, wit... Read more
Affected Products : homey- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-2048
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML via the sayfa parameter.... Read more
Affected Products : angelo-emlak- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2070
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to s... Read more
Affected Products : cpanel- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4732
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Tux Racer TuxBank 0.7x and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) description parameters.... Read more
Affected Products : tuxbank- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1285
Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF) 1.2 before 1.2_08 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : jsf- Published: Mar. 11, 2008
- Modified: Apr. 09, 2025