Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2508
Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.... Read more
Affected Products : tr_script_news- Published: May. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2814
Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; t... Read more
Affected Products : wallcity-server_shoutcast_admin_panel- Published: Jun. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-40692
Insufficient capability checks made it possible for teachers to download users outside of their courses.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2795
Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.... Read more
Affected Products : ultraedit- Published: Jun. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-20145
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control.... Read more
Affected Products : gitlab- Published: Jan. 13, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-20098
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTT... Read more
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2123
Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script or HTML via (1) a "<>" sequence in the ~service parameter to wgate.dll, or (2) Javascript splicing in th... Read more
Affected Products : internet_transaction_server- Published: May. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2115
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.... Read more
Affected Products : power_editor- Published: May. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-2550
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Logoff Page). The supported version that is affected is 12.0.2. Easily exploitable vulnerability allows unauthenticated attacker with ne... Read more
Affected Products : flexcube_direct_banking- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0893
The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.1.0. This makes it possible for authenticated att... Read more
Affected Products : schema_app_structured_data- Published: May. 24, 2024
- Modified: Apr. 04, 2025
-
4.3
MEDIUMCVE-2019-2564
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2176
Cross-site scripting (XSS) vulnerability in admin/category.php in Zomplog 3.8.2 allows remote attackers to inject arbitrary web script or HTML via the catname parameter.... Read more
Affected Products : zomplog- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2566
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.... Read more
Affected Products : php-address_book- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-20106
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a... Read more
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2117
Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.... Read more
Affected Products : project_alumni- Published: May. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2126
Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to index.php and the (2) returnURL parameter to tux-login.php.... Read more
Affected Products : tux_cms- Published: May. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-24695
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, un... Read more
Affected Products : bluetooth_core_specification- Published: Jun. 02, 2023
- Modified: Jan. 10, 2025
-
4.3
MEDIUMCVE-2006-0511
Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, s... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0649
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dataparksearch- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2496
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) login.php, and (3) credits.php in admin/, and (4) upgrade/index.php.... Read more
Affected Products : quate_cms- Published: May. 28, 2008
- Modified: Apr. 09, 2025