Latest CVE Feed
-
4.3
MEDIUMCVE-2010-4646
Cross-site scripting (XSS) vulnerability in Hastymail2 before 1.01 allows remote attackers to inject arbitrary web script or HTML via a crafted background attribute within a cell in a TABLE element, related to improper use of the htmLawed filter.... Read more
Affected Products : hastymail2- Published: Jan. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12280
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack... Read more
Affected Products : wp_customer_area- Published: Jan. 27, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2010-2763
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to by... Read more
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2509
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.... Read more
Affected Products : web_template_software- Published: Jun. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1224
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue m... Read more
Affected Products : websphere_mq- Published: Jul. 07, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4523
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : advantech_webaccess- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2778
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to a "Javascript XSS exploit."... Read more
Affected Products : groupwise- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4667
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : coppermine_photo_gallery- Published: Jun. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2995
Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service via unspecified vectors.... Read more
Affected Products : acrobat- Published: Oct. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2952
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to ... Read more
Affected Products : traffic_server- Published: Sep. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1246
Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Discl... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Jun. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4518
Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter.... Read more
- Published: Dec. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3003
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : insight_diagnostics- Published: Sep. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2846
Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the afmsg parameter to index.php.... Read more
- Published: Jul. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2742
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.... Read more
Affected Products : websphere_application_server- Published: Sep. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2959
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : buildbot- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-13883
The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to missing or incorrect nonce validation on the 'save_custom_css_request' function. This makes it possible f... Read more
- Published: Feb. 21, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2009-2887
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.... Read more
Affected Products : president_bios- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3003
Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, w... Read more
Affected Products : internet_explorer- Published: Aug. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2945
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers ... Read more
Affected Products : webauth- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025