Latest CVE Feed
-
4.3
MEDIUMCVE-2007-0607
W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request.... Read more
Affected Products : w-agora- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0547
Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : webform- Published: Jan. 29, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1606
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4)... Read more
Affected Products : w-agora- Published: Mar. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0998
The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrate... Read more
- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-2432
Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5873
Insufficient policy validation in navigation in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22924
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved ... Read more
- Published: Aug. 05, 2021
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2022-2303
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the ... Read more
Affected Products : gitlab- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5990
Cross-site scripting (XSS) vulnerability in ExoPHPdesk allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a user profile, possibly the (1) name and (2) website parameters to register.php.... Read more
Affected Products : exophpdesk- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-49080
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authenticated user include traceback info... Read more
Affected Products : jupyter_server- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-49094
Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response... Read more
Affected Products : symbolicator- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6857
Cross-site scripting (XSS) vulnerability in modules/credits/credits.php in Docebo LMS allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7149
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcnam... Read more
Affected Products : mambo- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7192
Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an x... Read more
Affected Products : .net_framework- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1610
Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via a feed.... Read more
Affected Products : newsglue- Published: Mar. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-2756
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthen... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight jdk jre e-series_santricity_os_controller +10 more products- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-7164
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information ... Read more
- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7165
IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."... Read more
Affected Products : websphere_application_server- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-22935
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.... Read more
Affected Products : salt- Published: Mar. 29, 2022
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2006-7190
Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic ins... Read more
Affected Products : webapp- Published: Apr. 03, 2007
- Modified: Apr. 09, 2025