Latest CVE Feed
-
4.3
MEDIUMCVE-2020-4687
IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should not have access to. IBM X-Force ID: 186679.... Read more
- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5121
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-1907
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxDeleteCategory function. This makes it possible for un... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2021-41613
An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective Address Register (EEAR) is not implemented correctly. User programs from authorized privilege levels will be unable to write to EEAR.... Read more
- Published: Apr. 18, 2023
- Modified: Mar. 05, 2025
-
4.3
MEDIUMCVE-2010-0865
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Business Suite 6.1.1.0 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-37939
Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Lite.This issue affects Patricia Lite: from n/a through 1.2.3.... Read more
Affected Products :- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5300
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2... Read more
Affected Products : open_source_security_information_management- Published: Aug. 15, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7108
Multiple cross-site scripting (XSS) vulnerabilities in Carmosa phpCart 3.4 through 4.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) quantity or (2) Add Engraving fields to the default URI; (3) Quantity field to phpcart.php; ... Read more
Affected Products : phpcart- Published: Aug. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5308
Cross-site scripting (XSS) vulnerability in the RealURL Management (realurlmanagement) extension 0.3.4 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-2643
Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject arbitrary web script or HTML via the user_error_message parameter.... Read more
Affected Products : monster_top_list- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-3291
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.... Read more
Affected Products : livecms- Published: Jun. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2882
Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter... Read more
Affected Products : phpcommunitycalendar- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-2085
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obta... Read more
Affected Products : essential_blocks- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6310
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.... Read more
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3247
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.... Read more
Affected Products : collabtive- Published: May. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-11354
The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the del_ytsingvid() function in all versions up to, and including, 3.3. This makes it possib... Read more
Affected Products : ultimate_youtube_video_\&_shorts_player_with_vimeo- Published: Nov. 21, 2024
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2007-4104
Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing bl... Read more
Affected Products : wordpress_plugin- Published: Jul. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4698
Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle att... Read more
- Published: Dec. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3834
Multiple cross-site scripting (XSS) vulnerabilities in Ex Libris ALEPH allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a URL that can be discovered through a keyword search. NOTE: this may be related to th... Read more
Affected Products : aleph- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-5513
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to File Manager.... Read more
- Published: Oct. 25, 2016
- Modified: May. 08, 2025