Latest CVE Feed
-
4.3
MEDIUMCVE-2021-31463
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malici... Read more
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-5840
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.... Read more
- Published: Jun. 27, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2380
Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."... Read more
Affected Products : windows_2000- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-31339
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework.... Read more
Affected Products : excel_importer- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-8769
An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29751
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.... Read more
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2417
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031.... Read more
Affected Products : phpmyadmin- Published: May. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-50052
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2006-7196
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the ... Read more
Affected Products : tomcat- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0240
Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.... Read more
Affected Products : zope- Published: Mar. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0494
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that conta... Read more
Affected Products : bind- Published: Jan. 25, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-31498
This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open ... Read more
Affected Products : brava\!_desktop- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10740
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modif... Read more
- Published: Apr. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1576
Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4)... Read more
Affected Products : phprojekt- Published: Mar. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-25025
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events... Read more
Affected Products : eventcalendar- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1000192
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.... Read more
- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10320
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a P... Read more
Affected Products : credentials- Published: May. 21, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1748
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character... Read more
- Published: Jun. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-25774
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.... Read more
Affected Products : teamcity- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30994
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to access local users' Apple IDs.... Read more
Affected Products : macos- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024