Latest CVE Feed
-
4.3
MEDIUMCVE-2024-5005
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose proje... Read more
Affected Products : gitlab- Published: Oct. 11, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2007-6474
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors.... Read more
Affected Products : gf_3xplorer- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-5075
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.... Read more
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2019-15592
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.... Read more
Affected Products : gitlab- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-11754
When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.... Read more
Affected Products : firefox- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27764
In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Pr... Read more
- Published: Dec. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-27465
Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which is supposed to be handled gracefully. Certain replayed in... Read more
Affected Products : xen- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2014-8122
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.... Read more
Affected Products : jboss_weld- Published: Feb. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2820
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP res... Read more
- Published: Nov. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-52227
Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.... Read more
Affected Products : mailerlite- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5638
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, whic... Read more
- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-27776
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned long. This would most likely lead ... Read more
- Published: Dec. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-6047
Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Sep. 25, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6424
registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbo... Read more
- Published: Dec. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-52060
A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.... Read more
Affected Products : gestsup- Published: Feb. 13, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2018-6052
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Sep. 25, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-15616
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.... Read more
Affected Products : nextcloud_server- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-17138
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : foxit_studio_photo- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6460
Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CV... Read more
Affected Products : anon_proxy_server- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4888
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.... Read more
Affected Products : xibo- Published: Jan. 29, 2014
- Modified: Apr. 11, 2025