Latest CVE Feed
-
4.3
MEDIUMCVE-2011-1263
Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Acce... Read more
Affected Products : windows_server_2008- Published: Aug. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3295
Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : open_guestbook- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0063
Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseov... Read more
- Published: Jan. 05, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-1903
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.... Read more
- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3918
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_server enterprise_linux_workstation http_server- Published: Jul. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-8723
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specia... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-1464
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.... Read more
- Published: Feb. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-6132
Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.... Read more
Affected Products : chrome- Published: Jun. 27, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1374
Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AIM is used, allows remote attackers to create arbitrary files via directory traversal sequences in an inline image-transfer operation.... Read more
- Published: Jun. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1143
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font.... Read more
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3138
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action paramete... Read more
Affected Products : phpmydirectory- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-40362
An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is... Read more
Affected Products : click2gov_building_permit- Published: Jan. 12, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2006-3883
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) table... Read more
Affected Products : linkscaffe- Published: Jul. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4583
Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).... Read more
Affected Products : esx- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4876
Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.2.2, and possibly other versions before 2.3.0 Beta 2, allows remote attackers to inject arbitrary web script or HTML via the user... Read more
Affected Products : openfire- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-39285
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful explo... Read more
Affected Products : mivoice_connect- Published: Sep. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-3081
Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.1... Read more
- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-3826
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.ph... Read more
Affected Products : boastmachine- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-2934
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to inject arbitrary web script or HTML via a crafted SVG f... Read more
Affected Products : mediawiki- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2933
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a LanguageConverter substitution string when using a la... Read more
Affected Products : mediawiki- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025