Latest CVE Feed
-
4.3
MEDIUMCVE-2011-5143
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.3.20 and probably earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tf_name, (2) tf_delegation, and (3) tf_ip parameters to index.php. ... Read more
Affected Products : open_business_management- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2932
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the selitems[] parameter in a (1) copy, (2) chmod, or (3) arch action to admin/index.php or (4) sear... Read more
Affected Products : tinywebgallery- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-3844
Apple Safari 5.0.5 does not properly implement the setInterval function, which allows remote attackers to spoof the address bar via a crafted web page.... Read more
Affected Products : safari- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3184
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Advanced UI... Read more
Affected Products : fusion_middleware- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4016
The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.... Read more
- Published: Sep. 28, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2917
Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the CDN API Key (cnd-key) in a share-and-follow-menu page to wp-admin/admin.php.... Read more
- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2960
Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.... Read more
- Published: Aug. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4018
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.... Read more
Affected Products : mywebsearch- Published: Oct. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2903
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.... Read more
Affected Products : php_address_book- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3272
Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before... Read more
- Published: Dec. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5024
Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web script or HTML via the config parameter.... Read more
Affected Products : mailman- Published: Dec. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5142
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tf_delegation, (2) tf_ip, or (3) tf_name parameter in a search ... Read more
Affected Products : open_business_management- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2304
The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an entity access module, does not check permissions when searching for entities, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2223
The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors.... Read more
Affected Products : zenworks_configuration_management- Published: Apr. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2243
Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this ... Read more
Affected Products : mahara- Published: Nov. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1904
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with sub... Read more
Affected Products : masterstudy_lms- Published: Apr. 09, 2024
- Modified: Jan. 17, 2025
-
4.3
MEDIUMCVE-2011-5084
Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : movable_type- Published: Apr. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-21206
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network ... Read more
Affected Products : enterprise_command_center_framework- Published: Oct. 15, 2024
- Modified: Jun. 23, 2025
-
4.3
MEDIUMCVE-2011-5221
Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.... Read more
Affected Products : websvn- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-13005
An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users... Read more
Affected Products : gitlab- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024