Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3009
Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.... Read more
Affected Products : cutenews- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1318
Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being prop... Read more
Affected Products : namazu- Published: Jan. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0194
Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.... Read more
Affected Products : fogbugz- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-23243
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app may be able to read sensitive location information.... Read more
- Published: Mar. 05, 2024
- Modified: Dec. 05, 2024
-
4.3
MEDIUMCVE-2006-4453
Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "table markups".... Read more
Affected Products : pmwiki- Published: Aug. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2476
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : shopping_cart- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3742
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.... Read more
Affected Products : advanced_poll- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4513
Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keywords parameter.... Read more
Affected Products : e-search- Published: Dec. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4583
Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).... Read more
Affected Products : esx- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2254
Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there... Read more
Affected Products : phpauction- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0758
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which i... Read more
Affected Products : hivemail- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2842
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.... Read more
Affected Products : cms- Published: Jun. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2413
Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : acgv_news- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0407
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the orig... Read more
Affected Products : az_bulletin_board- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-24872
The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction and v... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-33542
Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly Slider: from n/a through 1.4.5.... Read more
Affected Products : crelly_slider- Published: Apr. 29, 2024
- Modified: Aug. 27, 2025
-
4.3
MEDIUMCVE-2008-1545
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling att... Read more
Affected Products : internet_explorer- Published: Mar. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1541
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.... Read more
Affected Products : webshop- Published: Mar. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2458
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.... Read more
Affected Products : starsgames_control_panel- Published: May. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-23189
Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authorization