Latest CVE Feed
-
4.3
MEDIUMCVE-2018-1000185
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.... Read more
Affected Products : github_branch_source- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-14408
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-14170
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.... Read more
- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1716
Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when... Read more
Affected Products : burning_board- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2579
Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.... Read more
Affected Products : wp_simplemail- Published: Jun. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2890
Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.... Read more
Affected Products : riddles- Published: Aug. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3471
The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.... Read more
Affected Products : identity_services_engine_software- Published: Aug. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-39884
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.... Read more
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6993
Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the key parameter in a delete action to wp-admin/tools.php.... Read more
- Published: Jan. 03, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3149
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information... Read more
Affected Products : elgg- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-25671
A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a partial denial-of-service, prevent... Read more
Affected Products : rwg1.m12_firmware rwg1.m12d_firmware rwg1.m8_firmware rwg1.m12 rwg1.m12d rwg1.m8- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-6023
Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'.... Read more
Affected Products : office- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2202
A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : fortify_on_demand- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0865
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Business Suite 6.1.1.0 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2133
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete ac... Read more
Affected Products : pivot- Published: Jun. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5300
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2... Read more
Affected Products : open_source_security_information_management- Published: Aug. 15, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-24832
The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
Affected Products : wp_seo_redirect_301- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-7776
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.... Read more
Affected Products : u.motion_builder- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0248
Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.... Read more
Affected Products : rankem- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-9730
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025