Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13337
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setu... Read more
Affected Products : clearfy- Published: Apr. 12, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-27357
Cross-Site Request Forgery (CSRF) vulnerability in Musa AVCI Önceki Yazı Link allows Cross Site Request Forgery. This issue affects Önceki Yazı Link: from n/a through 1.3.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2009-4460
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.... Read more
Affected Products : auto-surf_traffic_exchange_script- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0754
Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitrary web script or HTML via the which parameter in a copy action.... Read more
Affected Products : wikyblog- Published: Feb. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4609
The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : rsa_netwitness_informer- Published: Dec. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-6121
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017 breach) , Proje... Read more
Affected Products : miner- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-38363
IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie wil... Read more
- Published: Nov. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-4485
Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a nod... Read more
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-47625
PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due to the invalid size check. A maliciou... Read more
Affected Products : px4_drone_autopilot- Published: Nov. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-0094
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.... Read more
Affected Products : active_management_technology_firmware- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-29705
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.... Read more
Affected Products : code-gen- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-5961
Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to inject arbitrary web script or HTML via the cID parameter in a document action. NOTE: the provenance of this information is unkno... Read more
Affected Products : tribiq_cms- Published: Jan. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-26903
Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery allows Cross Site Request Forgery. This issue affects InPost Gallery: from n/a through 2.1.4.3.... Read more
Affected Products : inpost_gallery- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-4336
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.... Read more
Affected Products : flogr- Published: Sep. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-6425
An information disclosure vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-32577085. References: QC-CR#1103689.... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4040
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.... Read more
- Published: Nov. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5786
Cross-site scripting (XSS) vulnerability in the Silva Find extension 1.1.5 and earlier in Silva 1.x before 1.6.3.2, Silva 2.0 before 2.0.12.2, and Silva 2.1 before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the fulltext par... Read more
- Published: Dec. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-26660
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls wi... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2018-2026
IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.... Read more
Affected Products : financial_transaction_manager- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3066
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.... Read more
Affected Products : perldiver- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025