Latest CVE Feed
-
4.3
MEDIUMCVE-2022-2630
An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2023-1417
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.... Read more
Affected Products : gitlab- Published: Apr. 05, 2023
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2024-43813
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2009-1749
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.... Read more
Affected Products : catviz- Published: May. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1553
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/conf... Read more
Affected Products : glassfish_server- Published: May. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3521
Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : tivoli_composite_application_manager_for_wesbsphere- Published: Oct. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1436
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_a... Read more
Affected Products : at1_event_publisher- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-1593
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.... Read more
Affected Products : profense_web_application_firewall- Published: May. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3485
Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI.... Read more
- Published: Sep. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3565
Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parame... Read more
Affected Products : intrushield_network_security_manager- Published: Nov. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-10798
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes... Read more
Affected Products : royal_elementor_addons- Published: Nov. 28, 2024
- Modified: Mar. 04, 2025
-
4.3
MEDIUMCVE-2024-10796
The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This mak... Read more
Affected Products : dynamic_content_personalization- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3540
Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : ultra_classifieds_pro- Published: Oct. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1418
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : system_management_homepage- Published: May. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1448
Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : apricot- Published: Apr. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1557
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/ma... Read more
Affected Products : wvc54gca- Published: May. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1349
Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI.... Read more
Affected Products : stronghold- Published: Apr. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3566
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulner... Read more
Affected Products : intrushield_network_security_manager- Published: Nov. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1333
Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body.... Read more
Affected Products : deskjet_6840- Published: Apr. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3530
Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.... Read more
Affected Products : radbids- Published: Oct. 02, 2009
- Modified: Apr. 09, 2025