Latest CVE Feed
-
4.3
MEDIUMCVE-2008-4370
Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php.... Read more
Affected Products : availscript_photo_album- Published: Oct. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3924
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direc... Read more
Affected Products : cmme- Published: Sep. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2787
Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter.... Read more
Affected Products : opendocman- Published: Jun. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1071
Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : dvguestbook- Published: Mar. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0763
Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.... Read more
Affected Products : escapade- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-3860
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotu... Read more
- Published: Aug. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2002-2086
Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via (1) "<<script" in unspecified input fields or (2) a javascript: URL in the src attribute of an ... Read more
Affected Products : squirrelmail- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0175
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.... Read more
Affected Products : openssh- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-4729
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 1725... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-8058
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful e... Read more
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-2734
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Execute on DBMS_ADVISOR privilege w... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4736
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172706.... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4745
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.... Read more
- Published: Feb. 24, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-0712
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.... Read more
Affected Products : exchange_server- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-2107
Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : openkeyserver- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-8172
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead... Read more
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-0624
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.... Read more
Affected Products : weblogic_server- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0792
Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter. NOTE: the provenance of this information is unknown; the details are obtained ... Read more
Affected Products : v-webmail- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0629
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.... Read more
Affected Products : peopletools- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-54705
Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.4.6.... Read more
Affected Products : event_manager_and_tickets_selling_for_woocommerce- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization