Latest CVE Feed
-
4.3
MEDIUMCVE-2007-2472
Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained so... Read more
Affected Products : sendcard- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-4189
Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Me... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2686
Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.... Read more
Affected Products : jetbox_cms- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4142
Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server 7.5.1 before 20070731 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a crafted Sametime meeting.... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-4183
Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4186
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-45101
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0.... Read more
Affected Products : customer_reviews_for_woocommerce- Published: Jan. 02, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-4089
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components.... Read more
Affected Products : vikingboard- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-2468
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: May. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2466
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: May. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2670
PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.... Read more
Affected Products : phpchain- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-1110
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-2756
The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.... Read more
Affected Products : libgd- Published: May. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4122
Unspecified vulnerability in Hitachi JP1/Cm2/Hierarchical Viewer (HV) 06-00 through 06-71-/B allows remote attackers to cause a denial of service (application stop and web interface outage) via certain "unexpected data."... Read more
Affected Products : jp1-cm2-hierarchical_viewer- Published: Aug. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-2901
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via DHCP to co... Read more
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6196
Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter.... Read more
Affected Products : atmail_webmail_system- Published: Dec. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-0768
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature ... Read more
- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2555
Unspecified vulnerability in Default.aspx in Podium CMS allows remote attackers to have an unknown impact, possibly session fixation, via a META HTTP-EQUIV Set-cookie expression in the id parameter, related to "cookie manipulation." NOTE: this issue migh... Read more
Affected Products : podium_cms- Published: May. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4102
Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3 Beta allows remote attackers to inject arbitrary HTML and web script via a leading '"/></> sequence in the search string.... Read more
Affected Products : sblog- Published: Jul. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-4581
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2... Read more
- Published: Sep. 11, 2023
- Modified: Nov. 21, 2024