Latest CVE Feed
-
4.3
MEDIUMCVE-2007-5798
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1)... Read more
Affected Products : websphere_application_server- Published: Nov. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2720
Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL.... Read more
Affected Products : gallery- Published: Jun. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-2987
Vulnerability in the Java SE product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compr... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2910
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with ne... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4428
Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.... Read more
Affected Products : cerberus_helpdesk- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-47401
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2007-5638
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, whic... Read more
- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4305
Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.... Read more
Affected Products : trac- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5809
Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-stat... Read more
Affected Products : ucosminexus_service_architect ucosminexus_service_platform cosminexus_server cosminexus_developer_light_version_6 cosminexus_developer_professional_version_6 cosminexus_developer_standard_version_6 ucosminexus_application_server_enterprise ucosminexus_application_server_standard ucosminexus_developer_light ucosminexus_developer_standard +4 more products- Published: Nov. 05, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4238
Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.... Read more
Affected Products : mantis- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-4828
Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development versions before 1.11.0 allows remote attackers to inject arbitrary web script o... Read more
Affected Products : mediawiki- Published: Sep. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-19004
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5034
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. ... Read more
Affected Products : elinks- Published: Sep. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-3288
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2006-5535
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to script... Read more
Affected Products : cpanel- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5530
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE... Read more
Affected Products : simpnews- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5560
Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE:... Read more
Affected Products : progsys- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5504
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action parameter.... Read more
Affected Products : simple_machines_forum- Published: Oct. 25, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6832
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.... Read more
Affected Products : joomla- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-4796
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).... Read more
Affected Products : snitz_forums_2000- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025