Latest CVE Feed
-
4.3
MEDIUMCVE-2007-2670
PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.... Read more
Affected Products : phpchain- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0371
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.... Read more
Affected Products : browsedialog_server- Published: Jan. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-48332
Missing Authorization vulnerability in Tech Banker Mail Bank - #1 Mail SMTP Plugin for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mail Bank - #1 Mail SMTP Plugin for WordPress: from n/a through 4.0... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2025-8580
Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2007-2686
Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.... Read more
Affected Products : jetbox_cms- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-8581
Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2007-2720
Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from t... Read more
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0649
Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the sr... Read more
- Published: Feb. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1714
Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to inject arbitrary web script ... Read more
- Published: Apr. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-4509
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.... Read more
- Published: Apr. 18, 2024
- Modified: Jul. 02, 2025
-
4.3
MEDIUMCVE-2007-2721
The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally d... Read more
Affected Products : jasper_jpeg-2000- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0242
The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that d... Read more
Affected Products : qt- Published: Apr. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4745
Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the si... Read more
- Published: Sep. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6089
Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) groupname (Group Name), or (3) detail (Message) field.... Read more
Affected Products : baalasp_forum- Published: Nov. 24, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1991
Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.... Read more
Affected Products : cmailserver- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1977
Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.... Read more
Affected Products : holacms- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-32979
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home director... Read more
Affected Products : email_extension- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
4.3
MEDIUMCVE-2007-2768
OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (O... Read more
Affected Products : hci_management_node solidfire openssh steelstore_cloud_integrated_storage hci_storage_node- Published: May. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4698
Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to conduct cross-site scripting (XSS) attacks by causing JavaScript events to be associated with the wrong frame.... Read more
Affected Products : safari- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1965
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.... Read more
Affected Products : content_management_system- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025