Latest CVE Feed
-
4.3
MEDIUMCVE-2012-5228
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details ar... Read more
Affected Products : phplist- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6541
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action ... Read more
Affected Products : neuron_news- Published: Dec. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2636
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_patio- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-20307
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.... Read more
Affected Products : virtual_traffic_manager- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4507
Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6243
Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.... Read more
Affected Products : ewww_image_optimizer_plugin- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-2700
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : clickbank_affiliate_marketplace_script- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3260
Cross-site scripting (XSS) vulnerability in index.php in vlbook 1.02 allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : vlbook- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-2540
Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.... Read more
Affected Products : opera_browser- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4333
Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.... Read more
Affected Products : php_infoboard- Published: Sep. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2723
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party infor... Read more
Affected Products : listserv- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2589
Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.... Read more
Affected Products : hutscripts_php_website_script- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3031
Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) w, (2) phcat, (3) dayid, and (4) calw parameters.... Read more
Affected Products : fipscms- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-20892
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4594
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.... Read more
Affected Products : payment_for_webform- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-20906
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4599
The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is set to a high value, allows remote attackers to cause a denial of service (process consumption) via multiple requests.... Read more
Affected Products : misery- Published: Jun. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-3817
A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CS... Read more
Affected Products : unified_computing_system_director- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-4939
Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote a... Read more
- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-10166
Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: C Oracle SSL API). Supported versions that are affected are FMW: 11.1.1.9.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows unauthenticated attacke... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025