Latest CVE Feed
-
4.3
MEDIUMCVE-2015-2747
Multiple cross-site scripting (XSS) vulnerabilities in the data loss prevention (DLP) incident Forensics Preview in Websense Triton 7.8.3 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via a crafted (1) email or ... Read more
- Published: Mar. 26, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-3051
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.... Read more
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2012-4909
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6254
Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or HTML via an attribute in a (1) device name, (2) device detail, (3) report name, (4) report detail, or (5) portlet ... Read more
Affected Products : zenoss_core- Published: Dec. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.... Read more
- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3862
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a... Read more
Affected Products : c-cda- Published: Sep. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5477
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.... Read more
- Published: Oct. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-8926
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-2869
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated atta... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-3400
sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.... Read more
Affected Products : zfs- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-6340
Cross-site scripting (XSS) vulnerability in the Vox populi (mv_vox_populi) extension 0.3.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-4409
The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for... Read more
Affected Products : woocommerce_etsy_integration- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-3647
Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter ... Read more
Affected Products : wp-photo-album-plus- Published: May. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4052
Multiple cross-site scripting (XSS) vulnerabilities in Jease before 2.9, when creating a comment, allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, or (3) comment parameter.... Read more
Affected Products : jease- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-4714
Cross-site scripting (XSS) vulnerability in the DreamBox DM500-S allows remote attackers to inject arbitrary web script or HTML via the mode parameter to /body.... Read more
- Published: Jun. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-4580
Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.... Read more
Affected Products : communique- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-4905
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-12973
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.... Read more
Affected Products : nimbus_jose\+jwt- Published: Aug. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-6063
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Tempo... Read more
Affected Products : word- Published: Feb. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6035
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2-STABLE allows remote attackers to inject arbitrary web script or HTML via the atknodetype parameter.... Read more
Affected Products : achievo- Published: Feb. 03, 2009
- Modified: Apr. 09, 2025