Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3776
Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.0 PR2 Rev 686 allow remote attackers to inject arbitrary web script or HTML via (1) the subject field when creating a new thread and (2) information passed to the Reputation s... Read more
Affected Products : mybulletinboard- Published: Nov. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-5653
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE... Read more
Affected Products : java_system_messenger_express- Published: Nov. 03, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2861
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly inj... Read more
Affected Products : n-stealth- Published: Sep. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-2246
The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the disclosure of contact information.... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2007-3991
Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM parameters;... Read more
Affected Products : cvmatik- Published: Jul. 25, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-13832
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to insufficient restrictions on which posts can be included. This makes it poss... Read more
Affected Products : ultra_addons_lite_for_elementor- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-0801
The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing or incorrect nonce validation on the 'rma-settings-wizard'. This makes it possible for unauthenti... Read more
Affected Products : ratemyagent- Published: Feb. 28, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2007-2896
Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2990
Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : vanillasoft_helpdesk- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-5537
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote attackers to inject arbitrary web script or HTML via the (1) upnp:settings/state or (2) upnp:settings/connection parame... Read more
Affected Products : dsl-g624t- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-37275
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the user, including ... Read more
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-5338
Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.... Read more
- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-3582
Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have access to, ... Read more
- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-8504
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.... Read more
Affected Products : yandex_browser- Published: Oct. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-13546
The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes it possible for authenticated attackers, with Contributor-level access... Read more
Affected Products : generateblocks- Published: Mar. 01, 2025
- Modified: Mar. 01, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2005-0629
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.... Read more
Affected Products : fourtwosevenbb- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-4424
Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribut... Read more
Affected Products : safari- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4078
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Text Ads Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) r parameter to (a) forgot_uid.php, the (2) query or (3) sk parameter to (b) search_results.php,... Read more
Affected Products : text_ads_enterprise- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-13337
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setu... Read more
Affected Products : clearfy- Published: Apr. 12, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2007-3792
Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/.... Read more
Affected Products : azdgdating- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025