Latest CVE Feed
-
4.3
MEDIUMCVE-2007-1125
Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.... Read more
Affected Products : simple_one-file_gallery- Published: Feb. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-48227
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versio... Read more
Affected Products : umbraco_cms- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0371
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2306
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to ex... Read more
Affected Products : virtual_war- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0451
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."... Read more
Affected Products : spamassassin- Published: Feb. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-1099
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countrie... Read more
Affected Products : oscommerce- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-49156
Missing Authorization vulnerability in GoDaddy GoDaddy Email Marketing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoDaddy Email Marketing: from n/a through 1.4.3.... Read more
Affected Products : godaddy_email_marketing- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2023-49835
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.... Read more
Affected Products : post_duplicator- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2007-1114
The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, a... Read more
- Published: Feb. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6142
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE:... Read more
Affected Products : jaf_cms- Published: Nov. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7209
Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to keywords results in the (1) main, (2) daily, (3) weekly, (4) monthly, (5) n... Read more
Affected Products : phptraffica- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-49877
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker ... Read more
- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1499
Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar... Read more
- Published: Mar. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5239
Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the query string (PHP_SELF) in kalender.php or (2) the captcha_session_code parameter in pre_details.php... Read more
Affected Products : expblog- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1529
The LLTD Responder in Microsoft Windows Vista does not send the Mapper a response to a DISCOVERY packet if another host has sent a spoofed response first, which allows remote attackers to spoof arbitrary hosts via a network-based race condition, aka the "... Read more
Affected Products : windows_vista- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1103
Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of tr... Read more
- Published: Feb. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6999
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.... Read more
Affected Products : deskpro- Published: Feb. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-48237
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the size of integer. Impact is low, user interaction is required and a crash may... Read more
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48235
Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an overflow. Ironically this happens in the existing overflow check, because the line number becomes negative and LONG_MAX - lnum will cause t... Read more
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024