Latest CVE Feed
-
4.3
MEDIUMCVE-2014-6153
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which mak... Read more
Affected Products : websphere_service_registry_and_repository- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-2437
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.... Read more
Affected Products : anecms_blog- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2453
Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which i... Read more
Affected Products : diskstation_manager dsm disk_station_ds1010\+ disk_station_ds109 disk_station_ds110\+ disk_station_ds110j disk_station_ds209 disk_station_ds210\+ disk_station_ds210j disk_station_ds409slim +4 more products- Published: Sep. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2455
Opera does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.... Read more
Affected Products : opera_browser- Published: Jun. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1218
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the f... Read more
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2463
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.... Read more
Affected Products : jamroom- Published: Jun. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-3253
An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list of all the users available in the application. ... Read more
Affected Products : nessus- Published: Aug. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12164
The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsslwp_reset_settings() function in all versions up to, and including, 1... Read more
Affected Products : wpsyncsheets- Published: Feb. 12, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2010-2458
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.... Read more
Affected Products : video_community_portal_script- Published: Jun. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2491
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.... Read more
Affected Products : roundup- Published: Sep. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2480
Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript ... Read more
Affected Products : mako- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2482
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-... Read more
Affected Products : libtiff- Published: Jul. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0377
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecifie... Read more
Affected Products : websphere_application_server- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-3398
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTT... Read more
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-0558
Unspecified vulnerability in the Oracle Service Contracts component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Renewals.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-2973
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated a... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-2406
The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by leveraging incorrect control of permissions on the PrintS... Read more
Affected Products : document_security_management- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-3611
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have... Read more
Affected Products : mattermost_server- Published: May. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2016-0536
Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to error messages.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5613
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5608.... Read more
Affected Products : vm_virtualbox- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025