Latest CVE Feed
-
4.3
MEDIUMCVE-2014-7987
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.... Read more
Affected Products : espocrm- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-2748
A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability ... Read more
Affected Products : enterprise_server- Published: Mar. 21, 2024
- Modified: Sep. 02, 2025
-
4.3
MEDIUMCVE-2014-4849
Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter.... Read more
Affected Products : foecms- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6240
Cross-site scripting (XSS) vulnerability in the Google Sitemap (weeaar_googlesitemap) extension 0.4.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : google_sitemap- Published: Sep. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-36736
The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to missing or incorrect nonce validation on the export_json, import_json, and sta... Read more
Affected Products : cartflows- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6312
Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripti... Read more
Affected Products : login_widget_with_shortcode- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6291
Cross-site scripting (XSS) vulnerability in the Alphabetic Sitemap (alpha_sitemap) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : alphabetic_sitemap- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4848
Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bs_blog_id parameter to wp-admin/options-general.php.... Read more
Affected Products : blogstand-smart-banner- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5018
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related t... Read more
Affected Products : limesurvey- Published: Jul. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6297
Cross-site scripting (XSS) vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mm_forum- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-4590
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML docume... Read more
- Published: Feb. 26, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-5103
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.... Read more
Affected Products : manageengine_eventlog_analyzer- Published: Jul. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-9819
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.... Read more
- Actively Exploited
- Published: Jun. 09, 2020
- Modified: Feb. 28, 2025
-
4.3
MEDIUMCVE-2023-48234
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been ... Read more
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6301
Multiple cross-site scripting (XSS) vulnerabilities in the tables-management module in PNMsoft Sequence Kinetics before 7.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : sequence_kinetics- Published: Feb. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6276
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-2960
The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the deletePricingTable() function. This makes it possible for unau... Read more
Affected Products : svs_pricing_tables- Published: May. 02, 2024
- Modified: Feb. 20, 2025
-
4.3
MEDIUMCVE-2014-4857
Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.... Read more
Affected Products : testrail- Published: Jul. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4423
The Accounts subsystem in Apple iOS before 8 allows attackers to bypass a sandbox protection mechanism and obtain an active iCloud account's Apple ID and metadata via a crafted application.... Read more
Affected Products : iphone_os- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-3322
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vu... Read more
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024