Latest CVE Feed
-
4.3
MEDIUMCVE-2014-6495
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4574
Cross-site scripting (XSS) vulnerability in resize.php in the WebEngage plugin before 2.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the height parameter.... Read more
Affected Products : webengage- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4958
Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other versions allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.... Read more
- Published: Sep. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-8053
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful e... Read more
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2169
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned.... Read more
Affected Products : manageengine_assetexplorer- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4632
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, ... Read more
Affected Products : vsphere_data_protection- Published: Feb. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4587
Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap plugin 1.8 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) zl, (2) mt, or (3) dc parameter to guest-locator.php; the (4) zl, (5) mt,... Read more
Affected Products : wp_guestmap_project- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-13457
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search results to disclose information from their "company" tickets (with the same CustomerID), even when the CustomerDisableCompanyTicketAccess ... Read more
Affected Products : otrs- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-3201
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.... Read more
Affected Products : surgemail- Published: Jan. 07, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6445
Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.... Read more
Affected Products : contact_form_7_integrations- Published: Sep. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4020
The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote atta... Read more
Affected Products : wireshark- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-40630
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected vers... Read more
Affected Products : openimageio- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4589
Cross-site scripting (XSS) vulnerability in uploader.php in the WP Silverlight Media Player (wp-media-player) plugin 0.8 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.... Read more
Affected Products : wp_silverlight_media_player- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4883
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning ... Read more
Affected Products : lwip- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4597
Cross-site scripting (XSS) vulnerability in test.php in the WP Social Invitations plugin before 1.4.4.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter.... Read more
Affected Products : wp_social_invitations- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4876
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.... Read more
Affected Products : 4690_operating_system- Published: Dec. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-29038
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.... Read more
Affected Products : tpm2-tools- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6462
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors related to Admin Console.... Read more
Affected Products : fusion_middleware- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-3638
Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Mac OS X, when Safari is used, allows attackers to obtain sensitive information via unknown vectors.... Read more
- Published: Nov. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6478
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025