Latest CVE Feed
-
4.3
MEDIUMCVE-2011-1038
Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the messageString parameter in a WebMessage action or (2) the PATH_INFO.... Read more
- Published: Feb. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4213
The Bank of America application 2.12 for Android stores a security question's answer in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.... Read more
- Published: Nov. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13317
The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or incorrect nonce validation on the 'shipworks-wordpress' page. This makes it pos... Read more
Affected Products :- Published: Jan. 18, 2025
- Modified: Jan. 18, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2009-4636
FFmpeg 0.5 allows remote attackers to cause a denial of service (hang) via a crafted file that triggers an infinite loop.... Read more
Affected Products : ffmpeg- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12596
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it pos... Read more
Affected Products : lifterlms- Published: Dec. 18, 2024
- Modified: Jul. 11, 2025
-
4.3
MEDIUMCVE-2024-13768
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_assign_... Read more
Affected Products :- Published: Mar. 22, 2025
- Modified: Mar. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2010-5314
Cross-site scripting (XSS) vulnerability in controllers/home_controller.php in BEdita before 3.1 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter to news/index.... Read more
- Published: Jan. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-4209
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfs... Read more
- Published: Nov. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4928
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML by placing it after a > (greater than) character.... Read more
- Published: Oct. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1053
Unspecified vulnerability in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (out-of-memory exception and inability to analyze code) via a crafted Mach-O file.... Read more
Affected Products : ida- Published: Feb. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1815
Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions.... Read more
Affected Products : chrome- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4947
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in ALLPC 2.5 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.... Read more
Affected Products : allpc- Published: Oct. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4960
Cross-site scripting (XSS) vulnerability in the Branchenbuch (aka Yellow Pages or mh_branchenbuch) extension before 0.9.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-8739
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure V... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2010-1361
Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter.... Read more
Affected Products : phpeppershop- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4949
Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified win... Read more
- Published: Oct. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0048
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scripting (XS... Read more
Affected Products : bugzilla- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4956
Cross-site scripting (XSS) vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1670
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit.... Read more
Affected Products : interra_blog_machine- Published: Apr. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4155
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) m... Read more
Affected Products : exv2- Published: Nov. 03, 2010
- Modified: Apr. 11, 2025