Latest CVE Feed
-
4.3
MEDIUMCVE-2009-3363
Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the "plain textarea editor."... Read more
- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-2271
The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack... Read more
Affected Products : tiempo- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4169
Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-47813
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.... Read more
Affected Products : wing_ftp_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2009-4196
Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) BackButton parameter to error_1; (2) w... Read more
Affected Products : mt882_v100t002b020_arg-t- Published: Dec. 04, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-37855
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser. ... Read more
Affected Products : wp_6070-wvps_firmware wp_6101-wxps_firmware wp_6121-wxps_firmware wp_6156-whps_firmware wp_6185-whps_firmware wp_6215-whps_firmware wp_6070-wvps wp_6101-wxps wp_6121-wxps wp_6156-whps +2 more products- Published: Aug. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12431
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.... Read more
Affected Products : gitlab- Published: Jan. 08, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2011-0533
Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related t... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-34750
A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege c... Read more
- Published: Nov. 15, 2024
- Modified: Aug. 06, 2025
-
4.3
MEDIUMCVE-2012-3438
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect ... Read more
Affected Products : graphicsmagick- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-58824
Missing Authorization vulnerability in webriti Shk Corporate allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shk Corporate: from n/a through 2.4.1.1.... Read more
Affected Products :- Published: Sep. 05, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-58817
Missing Authorization vulnerability in DesertThemes SoftMe allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SoftMe: from n/a through 1.1.24.... Read more
Affected Products :- Published: Sep. 05, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2012-1835
Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (... Read more
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4870
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.php; (3) clid or (4) clidname parame... Read more
- Published: Sep. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3274
Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle attackers to obtain sensitive directory information by leveraging a network position between CTS an... Read more
Affected Products : telepresence_system_software- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-30965
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2010-5275
Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2980
Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.... Read more
Affected Products : base- Published: Apr. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6808
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.... Read more
Affected Products : zendto- Published: Dec. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3892
Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : meridian- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025