Latest CVE Feed
-
4.3
MEDIUMCVE-2020-2216
A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified username and password.... Read more
Affected Products : zephyr_for_jira_test_management- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2258
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.... Read more
Affected Products : health_advisor_by_cloudbees- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2237
A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attackers to rebuild a project at a previous git revision.... Read more
Affected Products : flaky_test_handler- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-100028
Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted allows remote attackers to inject arbitrary web script or HTML via the username.... Read more
Affected Products : webcrafted- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6316
IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-selection changes during Taxonomy component rendering, which allows remote attackers to obtain sensitive property information in opportunisti... Read more
Affected Products : websphere_portal- Published: Dec. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6009
CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet.... Read more
Affected Products : open-xchange_appsuite- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2647
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : operations_agent- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2642
HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : system_management_homepage- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-100032
Cross-site scripting (XSS) vulnerability in top.html in the Airties Air 6372 modem allows remote attackers to inject arbitrary web script or HTML via the productboardtype parameter.... Read more
Affected Products : air_6372- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-100034
Cross-site scripting (XSS) vulnerability in the frontend interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : arcticdesk- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-10018
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote attackers to inject arbitrary web script or HTML via the essid parameter.... Read more
Affected Products : t2-b-gawv1.4u10y-bi- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2282
The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a c... Read more
Affected Products : wireshark- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2689
Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php.... Read more
Affected Products : offria- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-4002
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party ... Read more
Affected Products : drupal- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-6019
Cross-site scripting (XSS) vulnerability in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to inject arbitrary web script or HTML via the accountNum parameter to an unspecified component.... Read more
Affected Products : taxweb- Published: Oct. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9732
The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereferenc... Read more
- Published: Jun. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-100017
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the message field.... Read more
Affected Products : phponlinechat- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-1695
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame... Read more
Affected Products : safari- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-100026
Cross-site scripting (XSS) vulnerability in readme.php in the April's Super Functions Pack plugin before 1.4.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained f... Read more
Affected Products : april\'s_super_functions_pack- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2248
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : simatic_s7-1500_cpu_firmware- Published: Mar. 16, 2014
- Modified: Apr. 12, 2025