Latest CVE Feed
-
4.3
MEDIUMCVE-2025-4047
The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for au... Read more
Affected Products : broken_link_checker- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-4592
The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the 'wpz-ai-images' page. This makes it possib... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-0769
Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input.... Read more
Affected Products : livelink_ecm- Published: Feb. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-30425
This issue was addressed through improved state management. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to track users in Safari private browsing mode.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2011-1810
The Cascading Style Sheets (CSS) implementation in Google Chrome before 12.0.742.91 does not properly restrict access to the visit history, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : chrome- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0497
Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.... Read more
Affected Products : nucleus_cms- Published: Jan. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1811
Google Chrome before 12.0.742.91 does not properly handle a large number of form submissions, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.... Read more
Affected Products : chrome- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1937
Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.... Read more
Affected Products : webmin- Published: May. 31, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2083
Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3426
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.... Read more
Affected Products : iphone_os- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2192
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI r... Read more
- Published: Jul. 07, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2381
CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attach... Read more
Affected Products : bugzilla- Published: Aug. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3366
Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.... Read more
Affected Products : rekonq- Published: Nov. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2444
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "u... Read more
- Published: Sep. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3356
Multiple cross-site scripting (XSS) vulnerabilities in config_defaults_inc.php in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO, as demonstrated by the PATH_INFO to (1) manage_config_email_page.php, ... Read more
Affected Products : mantisbt- Published: Sep. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2598
The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the windows of arbitrary desktop applications via vectors involving an SVG filter, an IFRAME element, and uninitialized data in graphics memory.... Read more
Affected Products : firefox- Published: Jun. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2630
Opera before 11.11 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload occurring after the opening of a popup of the Easy Sticky Note extension.... Read more
Affected Products : opera_browser- Published: Jul. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7318
Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : firewall_analyzer- Published: Jan. 29, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-6069
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.... Read more
Affected Products : python- Published: Jun. 17, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2019-1645
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms for c... Read more
Affected Products : connected_mobile_experiences- Published: Jan. 24, 2019
- Modified: Nov. 21, 2024