Latest CVE Feed
-
4.3
MEDIUMCVE-2023-6385
The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.... Read more
Affected Products : wordpress_ping_optimizer- Published: Apr. 10, 2024
- Modified: May. 19, 2025
-
4.3
MEDIUMCVE-2008-3391
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.... Read more
Affected Products : web_wiz_forum- Published: Jul. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-3566
Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application hang) via JavaScript code that changes a form before submission.... Read more
Affected Products : opera_browser- Published: Jun. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-0810
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)... Read more
- Published: Jan. 24, 2024
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2008-2788
Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.... Read more
Affected Products : opendocman- Published: Jun. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2871
Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this infor... Read more
Affected Products : pegames- Published: Jun. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2776
Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely ... Read more
Affected Products : dt_centrepiece- Published: Jun. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2842
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.... Read more
Affected Products : cms- Published: Jun. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0649
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dataparksearch- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-24695
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, un... Read more
Affected Products : bluetooth_core_specification- Published: Jun. 02, 2023
- Modified: Jan. 10, 2025
-
4.3
MEDIUMCVE-2008-3243
Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft ... Read more
- Published: Jul. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2980
Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift]... Read more
Affected Products : homeph_design- Published: Jul. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-18655
Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.... Read more
Affected Products : prayer- Published: Oct. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3023
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a differ... Read more
- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3348
Cross-site scripting (XSS) vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the year parameter.... Read more
Affected Products : easydynamicpages- Published: Jul. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-40692
Insufficient capability checks made it possible for teachers to download users outside of their courses.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3344
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a allow remote attackers to inject arbitrary web script or HTML via the (1) ResultHtml, (2) dir, (3) SenderName,... Read more
Affected Products : easye-cards- Published: Jul. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2994
Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to ... Read more
Affected Products : phpeasydata- Published: Jul. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0893
The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.1.0. This makes it possible for authenticated att... Read more
Affected Products : schema_app_structured_data- Published: May. 24, 2024
- Modified: Apr. 04, 2025
-
4.3
MEDIUMCVE-2006-0846
Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the a... Read more
Affected Products : web_blog- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025