Latest CVE Feed
-
4.3
MEDIUMCVE-2006-6660
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.... Read more
Affected Products : libkhtml- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5626
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the ... Read more
Affected Products : phpfaber_content_management_system- Published: Oct. 31, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5598
Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.... Read more
Affected Products : goop_gallery- Published: Oct. 28, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-0643
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.... Read more
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4295
Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : panda_activescan- Published: Aug. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4091
Multiple cross-site scripting (XSS) vulnerabilities in Archangel Management Archangel Weblog 0.90.02 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Comment section.... Read more
Affected Products : weblog- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countrie... Read more
Affected Products : oscommerce- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-46254
capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and ... Read more
- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41975
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A website may be able to access the microphone without the microphone use indicator being shown.... Read more
Affected Products : macos- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5564
Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third par... Read more
Affected Products : md-pro- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5560
Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE:... Read more
Affected Products : progsys- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-41977
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, iOS 16.7.2 and iPadOS 16.7.2. Visiting a malicious website may reveal browsing history.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5255
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows... Read more
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5265
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitr... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-41241
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example,... Read more
- Published: Mar. 08, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6602
explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.... Read more
- Published: Dec. 15, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5268
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-5535
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to script... Read more
Affected Products : cpanel- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5331
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-5530
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE... Read more
Affected Products : simpnews- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025