Latest CVE Feed
-
4.3
MEDIUMCVE-2009-4848
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId parameter to tvserver/server/user/setPermissions.jsp, (2) d... Read more
Affected Products : virtualiq- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4839
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/base_roleadmin.php, (2) adm... Read more
Affected Products : basic_analysis_and_security_engine- Published: May. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-50779
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.... Read more
Affected Products : paaslane_estimate- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4822
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.... Read more
Affected Products : kasseler_cms- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4835
The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a... Read more
Affected Products : libsndfile- Published: May. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4465
Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.... Read more
Affected Products : lotus_mobile_connect- Published: Nov. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-1503
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers that could cause messages to no longer be transmitted via the affected channel. IBM X-Force ID: 141339.... Read more
Affected Products : websphere_mq- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0470
Unspecified vulnerability in Oracle Java SE 8u40 allows remote attackers to affect integrity via unknown vectors related to Hotspot.... Read more
- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-3246
Google Chrome before 6.0.472.53 does not properly handle the _blank value for the target attribute of unspecified elements, which allows remote attackers to bypass the pop-up blocker via unknown vectors.... Read more
Affected Products : chrome- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4246
Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (2) ifname parameter, a different vulnerability than CVE-2008-1182.... Read more
- Published: Dec. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3247
Google Chrome before 6.0.472.53 does not properly restrict the characters in URLs, which allows remote attackers to spoof the appearance of the URL bar via homographic sequences.... Read more
Affected Products : chrome- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4813
Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.... Read more
Affected Products : mybb- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1557
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/ma... Read more
Affected Products : wvc54gca- Published: May. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3200
MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_... Read more
Affected Products : word- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4782
Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) forum, and (3) cat parameters to community/thread.php; (4) start and (5) cat parameters ... Read more
Affected Products : theeta_cms- Published: Apr. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-14782
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthentica... Read more
- Published: Oct. 21, 2020
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2020-14781
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated a... Read more
Affected Products : debian_linux leap active_iq_unified_manager hci_management_node solidfire oncommand_insight jdk jre e-series_santricity_os_controller e-series_santricity_storage_manager +7 more products- Published: Oct. 21, 2020
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2009-4804
Cross-site scripting (XSS) vulnerability in the Calendar Base (cal) extension before 1.1.1 for TYPO3, when Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via "search parameters."... Read more
- Published: Apr. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4786
Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/admin_config.php, (2) admin/admin_modules.php, (3) delete.php, (4) editlink.ph... Read more
Affected Products : pligg_cms- Published: Apr. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4772
Unspecified vulnerability in the PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal, when a custom checkout completion message is enabled, allows attackers to obtain sensitive informa... Read more
- Published: Apr. 20, 2010
- Modified: Apr. 11, 2025