Latest CVE Feed
-
4.3
MEDIUMCVE-2009-4497
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program.... Read more
- Published: Jan. 07, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0938
Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action.... Read more
Affected Products : todoo_forum- Published: Mar. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0335
Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2952
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to ... Read more
Affected Products : traffic_server- Published: Sep. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4518
Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via an inserted node.... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4944
Multiple cross-site scripting (XSS) vulnerabilities in ATRC ACollab 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) address parameter to profile.php or the (2) description parameter to events/add_event.php. NOTE: the provena... Read more
Affected Products : acollab- Published: Jul. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2013
Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : lisk_cms- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-11111
Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2009-4937
Cross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1 allows remote attackers to inject arbitrary web script or HTML via an onmouseover action in an img BBCode tag within a url BBCode tag.... Read more
Affected Products : small_pirate- Published: Jul. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2084
Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.... Read more
Affected Products : asp.net- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4857
Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : php_photo_vote1.3f- Published: May. 11, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1723
The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 processes key messages after destruction by a dispatched event listener, which allows remote attackers to cause a denial of service (application crash)... Read more
- Published: Sep. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5257
Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter related to the Twitter widget and (2) facebook_id parame... Read more
- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12033
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscribe... Read more
Affected Products : jupiter_x_core- Published: Jan. 07, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2010-0432
Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStore... Read more
Affected Products : ofbiz- Published: Apr. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4521
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report p... Read more
Affected Products : birt- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0940
Cross-site scripting (XSS) vulnerability in guestbook.php in Simple PHP Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : simple_php_guestbook- Published: Mar. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1976
Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : application_server- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4554
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or ... Read more
Affected Products : snitz_forums_2000- Published: Jan. 04, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2010
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : ctools- Published: May. 21, 2010
- Modified: Apr. 11, 2025