Latest CVE Feed
-
4.3
MEDIUMCVE-2023-5963
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax opera... Read more
Affected Products : gitlab- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1832
Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut ... Read more
Affected Products : mybulletinboard- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-36903
A missing permission check in Jenkins Repository Connector Plugin 2.2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : repository_connector- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2631
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.... Read more
Affected Products : code_dx- Published: May. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36904
Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkin... Read more
Affected Products : repository_connector- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36897
A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : compuware_xpediter_code_coverage- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36892
Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-sp... Read more
Affected Products : rhnpush-plugin- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36886
A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job.... Read more
Affected Products : external_monitor_job_type- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-36002
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.... Read more
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1866
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.... Read more
Affected Products : calendarix_advanced- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-34994
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directo... Read more
- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3477
Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by In... Read more
Affected Products : invision_gallery- Published: Nov. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2688
Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal 3.4 allow remote attackers to inject arbitrary web script or HTML via a large number of parameters to (1) footer.php, (2) header.php, (3) menu_dx.php, or (4) menu_sx.php, or Javascript c... Read more
Affected Products : savewebportal- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1769
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.... Read more
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-39419
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to... Read more
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-30518
A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : thycotic_secret_server- Published: Apr. 12, 2023
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2005-2453
Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : networkactiv_web_server- Published: Aug. 04, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0641
Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.... Read more
Affected Products : unicenter_asset_management- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-35984
The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An attacker in physical proximity can cause a limited out of bounds write.... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1316
Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : accounts- Published: May. 02, 2005
- Modified: Apr. 03, 2025