Latest CVE Feed
-
4.3
MEDIUMCVE-2018-1044
In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.... Read more
Affected Products : moodle- Published: Jan. 22, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-37954
A cross-site request forgery (CSRF) vulnerability in Jenkins Rebuilder Plugin 320.v5a_0933a_e7d61 and earlier allows attackers to rebuild a previous build.... Read more
Affected Products : rebuilder- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3959
Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before bein... Read more
Affected Products : freewebstat- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3971
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.... Read more
- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4053
Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html.... Read more
Affected Products : cowiki- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3908
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.... Read more
Affected Products : amazon_shop- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-2404
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 through 20250916. NOTE: The vendor did no... Read more
Affected Products :- Published: Sep. 16, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2023-37945
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.... Read more
Affected Products : saml_single_sign_on- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3867
Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.... Read more
Affected Products : revenuepilot_search_engine_script- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3851
Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.... Read more
Affected Products : oasys_lite- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3841
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.... Read more
Affected Products : kplaylist- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3866
Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.... Read more
Affected Products : searchfeed_search_engine- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3818
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parame... Read more
Affected Products : vtiger_crm- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3814
Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php, (2) frames.php, and (3) search.php.... Read more
Affected Products : smartppc_pro- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-28159
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.... Read more
Affected Products : subversion_partial_release_manager- Published: Mar. 06, 2024
- Modified: Jun. 06, 2025
-
4.3
MEDIUMCVE-2024-28155
Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available scan config names, engine group names, and client names.... Read more
Affected Products : appspider- Published: Mar. 06, 2024
- Modified: Mar. 29, 2025
-
4.3
MEDIUMCVE-2012-4142
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores some characters in HTML documents in unspecified circumstances, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks vi... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4168
Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.... Read more
- Published: Aug. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-2001
Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector.... Read more
Affected Products : scry_gallery- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2025
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows ... Read more
- Published: Apr. 09, 2009
- Modified: Apr. 09, 2025