Latest CVE Feed
-
4.3
MEDIUMCVE-2012-2582
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote... Read more
- Published: Aug. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-13676
Insufficient policy enforcement in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.... Read more
Affected Products : chrome- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-2087
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/erro... Read more
- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-36843
The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new vali... Read more
Affected Products :- Published: Mar. 13, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Cryptography
-
4.3
MEDIUMCVE-2012-1099
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web scr... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-3764
Notification Center in Apple OS X before 10.10.5 does not properly remove dismissed notifications, which allows attackers to read arbitrary notifications via a crafted app.... Read more
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.... Read more
Affected Products : wpmarketplace- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-32082
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have re... Read more
Affected Products : etcd- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5441
Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) crea... Read more
- Published: Sep. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9031
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field... Read more
Affected Products : wordpress- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9032
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wordpress- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5444
Geary before 0.6.3 does not present the user with a warning when a TLS certificate error is detected, which makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted certificate.... Read more
Affected Products : geary- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9036
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a ... Read more
- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-0124
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a... Read more
Affected Products : serendipity- Published: Feb. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4209
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it ... Read more
Affected Products : firefox firefox_esr thunderbird ubuntu_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_eus opensuse linux_enterprise_server +4 more products- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0959
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName paramete... Read more
Affected Products : unified_operations_manager- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9035
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9059
lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 charact... Read more
Affected Products : moodle- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0581
Multiple CRLF injection vulnerabilities in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified tags.... Read more
Affected Products : coldfusion- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9094
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand param... Read more
Affected Products : video_gallery- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025