Latest CVE Feed
-
4.3
MEDIUMCVE-2016-6024
IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-2117
Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.... Read more
- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2209
Cross-site scripting (XSS) vulnerability in the auto-complete widget in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17 and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary web script or HTML via a full name.... Read more
- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-3439
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript f... Read more
- Published: Aug. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-2449
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attacker... Read more
Affected Products : tomcat- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6430
Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address whe... Read more
- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6037
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not ... Read more
Affected Products : mahara- Published: Nov. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6306
Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords att... Read more
- Published: Dec. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2808
Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.... Read more
- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6203
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web cl... Read more
Affected Products : http_server- Published: Dec. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6272
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1) help/sm/en/Output... Read more
Affected Products : openmanage_server_administrator- Published: Jan. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-8475
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and preven... Read more
Affected Products : freebsd- Published: Nov. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20372
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518.... Read more
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6110
Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.... Read more
Affected Products : htdig- Published: Nov. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-6625
An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to... Read more
Affected Products : phpmyadmin- Published: Dec. 11, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20747
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an arbitrary website via the vulnerab... Read more
Affected Products : retty- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20450
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user g... Read more
Affected Products : cognos_controller- Published: May. 03, 2024
- Modified: Jun. 18, 2025
-
4.3
MEDIUMCVE-2013-0010
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," ... Read more
Affected Products : system_center_operations_manager- Published: Jan. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-20768
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.... Read more
Affected Products : garoon- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20788
Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the ver... Read more
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024