Latest CVE Feed
-
4.3
MEDIUMCVE-2011-1838
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.... Read more
Affected Products : twiki- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4748
Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : pmwiki- Published: Mar. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3562
Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1400
The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, w... Read more
Affected Products : mollie_forms- Published: Mar. 11, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2011-4726
Multiple cross-site scripting (XSS) vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by a... Read more
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4757
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obt... Read more
Affected Products : e107- Published: Mar. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1396
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component.... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13118
The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack... Read more
Affected Products : ip_based_login- Published: Mar. 25, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2011-1890
Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."... Read more
- Published: Sep. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3513
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity, related to HTML Pages.... Read more
Affected Products : e-business_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4747
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.... Read more
- Published: Mar. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3881
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection ... Read more
- Published: Oct. 25, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4766
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstanc... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1650
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated a... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2011-3970
libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.... Read more
- Published: Feb. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1645
The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportRegistrations function in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with ... Read more
Affected Products : mollie_forms- Published: Mar. 11, 2024
- Modified: Jan. 21, 2025
-
4.3
MEDIUMCVE-2023-4903
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4776
Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/update/sett... Read more
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3864
Cross-site scripting (XSS) vulnerability in the The Erudite theme before 2.7.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2694
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows... Read more
- Published: Jun. 22, 2012
- Modified: Apr. 11, 2025