Latest CVE Feed
-
4.3
MEDIUMCVE-2019-19259
GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).... Read more
Affected Products : gitlab- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9706
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-30523
Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the... Read more
Affected Products : report_portal- Published: Apr. 12, 2023
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2023-30518
A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : thycotic_secret_server- Published: Apr. 12, 2023
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2019-15733
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.... Read more
Affected Products : gitlab- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33586
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.... Read more
- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2820
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".... Read more
Affected Products : sqwebmail- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-28152
A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to restore the default ownership of a job.... Read more
Affected Products : job_and_node_ownership- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2523
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1622
Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.... Read more
Affected Products : metacart_e-shop- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0270
Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report pa... Read more
Affected Products : reviewpost_php_pro- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2568
Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.... Read more
Affected Products : recipants- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-32344
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.... Read more
- Published: Feb. 26, 2024
- Modified: Dec. 17, 2024
-
4.3
MEDIUMCVE-2020-3781
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-0264
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.... Read more
Affected Products : owl_intranet_engine- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1587
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.... Read more
Affected Products : quick.cart- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1555
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.... Read more
Affected Products : coldfusion- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-3771
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1557
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.... Read more
Affected Products : guestbook_pro- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-32988
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : azure_vm_agents- Published: May. 16, 2023
- Modified: Jan. 23, 2025