Latest CVE Feed
-
4.3
MEDIUMCVE-2014-2244
Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via... Read more
Affected Products : mediawiki- Published: Mar. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3179
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."... Read more
- Published: Sep. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1456
Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.... Read more
Affected Products : open_web_analytics- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-4322
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, whi... Read more
Affected Products : tomcat- Published: Feb. 26, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 ... Read more
- Published: Mar. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-0459
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or... Read more
Affected Products : websphere_application_server- Published: Jan. 27, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6637
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE:... Read more
Affected Products : flash_player- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5118
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.... Read more
Affected Products : good_for_enterprise- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0298
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted iCalendar file to the calendar application, the (2) dir or (3) file parameter to apps/files_... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0272
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.... Read more
Affected Products : groupwise- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1804
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions ... Read more
- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-4346
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.... Read more
Affected Products : python-oauth2- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1759
Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field.... Read more
Affected Products : responsive_logo_slideshow- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-23561
HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. ... Read more
- Published: Apr. 15, 2024
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0240
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."... Read more
Affected Products : java_system_identity_manager- Published: Jan. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-2678
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulne... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4433
Cross-site scripting (XSS) vulnerability in XHProf before 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the run parameter.... Read more
Affected Products : xhprof- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-1710
The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a file... Read more
Affected Products : php- Published: Mar. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5013
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web script or HTML via (1) vectors involving PHP scripts and (2) unspecified ot... Read more
Affected Products : web_gateway- Published: Feb. 11, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1770
Cross-site scripting (XSS) vulnerability in views_view.php in Ganglia Web 3.5.7 allows remote attackers to inject arbitrary web script or HTML via the view_name parameter.... Read more
Affected Products : ganglia-web- Published: Apr. 02, 2014
- Modified: Apr. 12, 2025