Latest CVE Feed
-
4.3
MEDIUMCVE-2023-4509
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.... Read more
- Published: Apr. 18, 2024
- Modified: Jul. 02, 2025
-
4.3
MEDIUMCVE-2007-3426
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
Affected Products : phptraffica- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3366
Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unk... Read more
Affected Products : cpanel- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3396
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.... Read more
Affected Products : kf_web_server- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1991
Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.... Read more
Affected Products : cmailserver- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3406
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) s... Read more
- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1977
Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.... Read more
Affected Products : holacms- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1965
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.... Read more
Affected Products : content_management_system- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-3444
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)... Read more
Affected Products : chrome- Published: Nov. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4629
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the 'ladipage_con... Read more
Affected Products : ladipage- Published: Mar. 12, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2022-3351
An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3316
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Nov. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1950
Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter.... Read more
Affected Products : content_management_system- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3412
Cross-site scripting (XSS) vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter.... Read more
Affected Products : clickgallery- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3413
Multiple cross-site scripting (XSS) vulnerabilities in bosDataGrid 2.50 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GridSearch, (2) gsearch, or (3) ParentID parameter to an unspecified component.... Read more
Affected Products : bosdatagrid- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3417
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search string, which is not sanitized when an HREF attribute is print... Read more
Affected Products : webapp- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-32795
This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. Visiting a malicious website may lead to address bar spoofing.... Read more
- Published: Sep. 20, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1901
SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum.php, and the (3) id parameter to (a) viewforum.php or (b) members.php, which reveal the installation path in the r... Read more
Affected Products : sonicbb- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3445
Buffer overflow in SJ Labs SJphone 1.60.303c, running under Windows Mobile 2003 on the Samsung SCH-i730 phone, allows remote attackers to cause a denial of service (device hang and call termination) via a malformed SIP INVITE message, a different vulnerab... Read more
- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-4364
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024