Latest CVE Feed
-
4.3
MEDIUMCVE-2020-4673
IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.... Read more
Affected Products : workload_automation- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8584
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web-dorado_spider_video_player- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7987
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.... Read more
Affected Products : espocrm- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0497
Unspecified vulnerability in the PeopleSoft Enterprise Portal Interaction Hub component in Oracle PeopleSoft Products 9.1.00 allows remote attackers to affect integrity via unknown vectors related to Enterprise Portal.... Read more
Affected Products : peoplesoft_products- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7277
Cross-site scripting (XSS) vulnerability in the login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified "welcome message" form data that is i... Read more
- Published: Oct. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter to admin/contacts/contacts/add page; (2) data[Block][title] or (3) data[Blo... Read more
Affected Products : croogo- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7291
Multiple cross-site scripting (XSS) vulnerabilities in api_events.php in Springshare LibCal 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) m or (2) cid parameter.... Read more
Affected Products : libcal- Published: Dec. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1404
Cross-site scripting (XSS) vulnerability in the Content Rating Extbase extension 2.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : content_rating_extbase- Published: Feb. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0605
The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.... Read more
- Published: Feb. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0707
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.... Read more
Affected Products : mailman- Published: Feb. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-25766
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : azure_credentials- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
4.3
MEDIUMCVE-2021-2343
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with net... Read more
Affected Products : workflow- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0553
Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.... Read more
Affected Products : websitebaker- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8600
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) t... Read more
- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-31897
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated atta... Read more
Affected Products : cloud_pak_for_business_automation- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-7144
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remo... Read more
- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-31894
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.... Read more
Affected Products : app_connect_enterprise- Published: May. 22, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2014-9143
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.... Read more
Affected Products : td5130_router_firmware- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1179
Multiple cross-site scripting (XSS) vulnerabilities in data_point_details.shtm in Mango Automation 2.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dpid, (2) dpxid, or (3) pid parameter.... Read more
- Published: Jan. 26, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7413
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- Published: Dec. 21, 2015
- Modified: Apr. 12, 2025