Latest CVE Feed
-
4.3
MEDIUMCVE-2021-44185
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASL... Read more
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0118
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.... Read more
Affected Products : edittag- Published: Jan. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-39902
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.... Read more
Affected Products : gitlab- Published: Nov. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4509
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.... Read more
- Published: Apr. 18, 2024
- Modified: Jul. 02, 2025
-
4.3
MEDIUMCVE-2007-1361
Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart before 20070213 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue is probably different than CVE-2007-0376.... Read more
Affected Products : virtuemart- Published: Mar. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-13659
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.... Read more
Affected Products : chrome- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39870
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-43754
Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” sett... Read more
- Published: Nov. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0788
Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "sortable tables JavaScript."... Read more
Affected Products : mediawiki- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0045
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer... Read more
- Published: Jan. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-7152
An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail Message Framework" component. It allows remote attackers to spoof the address bar via a crafted web site.... Read more
Affected Products : iphone_os- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-4365
Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1905
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "&l... Read more
Affected Products : quizshock- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-49674
A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.... Read more
Affected Products : neuvector_vulnerability_scanner- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4532
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects whic... Read more
Affected Products : gitlab- Published: Sep. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0798
Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTM... Read more
Affected Products : ublog_reload- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5447
Cross-site scripting (XSS) vulnerability in index.php in DEV Web Management System (WMS) 1.5 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : dev_web_management_system- Published: Oct. 23, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1328
Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard JOLY BJ Webring allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter related to the add link menu.... Read more
Affected Products : bj_webring- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5486
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.... Read more
- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-48653
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.... Read more
- Published: Feb. 29, 2024
- Modified: Dec. 16, 2024