Latest CVE Feed
-
4.3
MEDIUMCVE-2016-3000
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-1637
Multiple cross-site scripting (XSS) vulnerabilities in aWebBB 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) tname or (2) fpost parameters to (a) post.php; (3) fullname, (4) emailadd, (5) country, (6) sig, or (7) otherav par... Read more
Affected Products : awebbb- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-32282
Cross-Site Request Forgery (CSRF) vulnerability in ShareThis ShareThis Dashboard for Google Analytics. This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.2.2.... Read more
Affected Products : dashboard_for_google_analytics- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-30804
Cross-Site Request Forgery (CSRF) vulnerability in maennchen1.de wpShopGermany IT-RECHT KANZLEI allows Cross Site Request Forgery. This issue affects wpShopGermany IT-RECHT KANZLEI: from n/a through 2.0.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2019-10189
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.... Read more
Affected Products : moodle- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2861
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly inj... Read more
Affected Products : n-stealth- Published: Sep. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-40834
A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage thi... Read more
Affected Products : safe- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4289
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.... Read more
Affected Products : edatcat_shopping_cart_system- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0860
Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.... Read more
Affected Products : netmri- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-5073
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to contact_support.php; (2) contractid parameter to contract_ad... Read more
Affected Products : support_incident_tracker- Published: Jan. 29, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2818
Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.... Read more
Affected Products : downfile- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-0370
Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : cpanel- Published: Jan. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-4015
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.... Read more
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-5080
Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4764
Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrate... Read more
Affected Products : parallels_plesk_small_business_panel- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0388
Unspecified vulnerability in the PeopleSoft HRMS component in Oracle PeopleSoft Products 9.1 allows remote attackers to affect integrity via unknown vectors related to Mobile Company Directory.... Read more
Affected Products : peoplesoft_products- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4485
Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a nod... Read more
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10323
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : artifactory- Published: May. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-36751
The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_meta() function. This makes it possible for unauthenticated attacke... Read more
Affected Products : coupon_creator- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-4048
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject arbitrary text messages. Users may g... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 15, 2016
- Modified: Apr. 12, 2025