Latest CVE Feed
-
4.3
MEDIUMCVE-2019-4743
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8247
Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.... Read more
Affected Products : internet_management_software- Published: Dec. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-1716
Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when... Read more
Affected Products : burning_board- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-2522
Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP... Read more
Affected Products : knowledge- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5487
Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows remote authenticated users with the "view meta information" permission to inject arbitrary web script or HTML via uns... Read more
Affected Products : camtasia_relay- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-0248
Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.... Read more
Affected Products : rankem- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-27584
When a user opens manipulated PhotoShop Document (.PSD) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-14170
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.... Read more
- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-4395
Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the redirect_url parameter.... Read more
- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-49383
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.... Read more
- Published: Oct. 15, 2024
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2010-0875
Unspecified vulnerability in the Life Sciences - Oracle Thesaurus Management System component in Oracle Industry Product Suite 4.5.2, 4.6, and 4.6.1 allows remote attackers to affect integrity, related to TMS Browser.... Read more
Affected Products : industry_product_suite- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-2110
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes... Read more
Affected Products : events_manager- Published: Mar. 28, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2019-0393
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.... Read more
Affected Products : quality_management- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0533
Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this informatio... Read more
Affected Products : ez_reminder- Published: Feb. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4544
Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-1501
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.... Read more
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-12213
A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. T... Read more
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-0190
Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[tab... Read more
Affected Products : awesometemplateengine- Published: Jan. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0215
Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter. NOTE: this issue might be resultant from CVE-2006-0216.... Read more
Affected Products : quality_ppc- Published: Jan. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5010
Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via the URL to webbatch.exe.... Read more
Affected Products : webbatch- Published: Sep. 20, 2007
- Modified: Apr. 09, 2025