Latest CVE Feed
-
4.3
MEDIUMCVE-2021-26999
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version whi... Read more
Affected Products : cloud_manager- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4373
The in_mp4 plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via crafted (1) metadata or (2) albumart in an invalid MP4 file.... Read more
Affected Products : winamp- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-24281
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.... Read more
Affected Products : redirection_for_contact_form_7- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4374
The in_mkv plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via a Matroska Video (MKV) file containing a string with a crafted length.... Read more
Affected Products : winamp- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4348
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the db_type parameter, related to an unsafe call by MantisBT to a function in the ADOdb Li... Read more
Affected Products : mantisbt- Published: Jan. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4410
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to no... Read more
- Published: Dec. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-25430
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-7196
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the ... Read more
Affected Products : tomcat- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0240
Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.... Read more
Affected Products : zope- Published: Mar. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-1000193
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to ha... Read more
- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-28485
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not inten... Read more
Affected Products : mobile_switching_center_server_bc_18a_firmware mobile_switching_center_server_bc_18a- Published: Sep. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1956
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site sc... Read more
- Published: Aug. 29, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-24251
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4317
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal c... Read more
Affected Products : postgresql- Published: May. 14, 2024
- Modified: Mar. 28, 2025
-
4.3
MEDIUMCVE-2021-30803
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access a user’s recent Contacts.... Read more
Affected Products : macos- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3236
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.... Read more
Affected Products : gimp- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3425
The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a ... Read more
- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3499
Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2... Read more
Affected Products : http_server- Published: Feb. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-24207
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.... Read more
Affected Products : wp_page_builder- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5386
Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : phpmyadmin- Published: Oct. 12, 2007
- Modified: Apr. 09, 2025