Latest CVE Feed
-
4.3
MEDIUMCVE-2008-3404
Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the link parameter.... Read more
Affected Products : mjguest- Published: Jul. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3735
Cross-site scripting (XSS) vulnerability in index.php in PHPizabi before 848 Core HotFix Pack 3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a blogs.search action.... Read more
Affected Products : phpizabi- Published: Aug. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0978
Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and ... Read more
Affected Products : argosoft_mail_server- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-2925
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP... Read more
Affected Products : workflow- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4288
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160631.... Read more
Affected Products : maximo_anywhere- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4729
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 1725... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-3981
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.... Read more
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4257
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.... Read more
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-3990
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can b... Read more
Affected Products : harbor- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2887
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with... Read more
Affected Products : weblogic_server- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2166
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.... Read more
Affected Products : java_system_web_server- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-2933
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthentica... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4330
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.... Read more
Affected Products : security_guardium_big_data_intelligence- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-1999-0877
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.... Read more
Affected Products : internet_explorer- Published: Oct. 01, 1999
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-3779
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action.... Read more
Affected Products : five_star_review_script- Published: Aug. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-4603
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user. IBM X-Force ID: 168295.... Read more
Affected Products : rational_quality_manager- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4047
IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.... Read more
Affected Products : jazz_reporting_service- Published: Apr. 29, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5533
In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and... Read more
Affected Products : sd-wan_by_velocloud- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-6212
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel_mese and (2) sel_anno parameters in a systems action. NOTE: the provenance of this information is unk... Read more
Affected Products : php-stats- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1333
Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body.... Read more
Affected Products : deskjet_6840- Published: Apr. 17, 2009
- Modified: Apr. 09, 2025