Latest CVE Feed
-
4.3
MEDIUMCVE-2024-11111
Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2010-3514
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remote attackers to affect integrity via unknown vectors related to Web Container.... Read more
Affected Products : sun_products_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4547
Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter to forums.php, or the forum_id parameter to (2) forum.php or (3) forum_topic_new.php.... Read more
Affected Products : viart_cms- Published: Jan. 04, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4563
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_... Read more
Affected Products : zenphoto- Published: Jan. 04, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4575
Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_sira parameter in a sirala action to index.php.... Read more
- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4447
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1803
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validati... Read more
Affected Products : embedpress- Published: May. 23, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for... Read more
Affected Products : wordpress- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4525
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via crafted data in a list o... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4524
Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (aka real name) element.... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4497
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program.... Read more
- Published: Jan. 07, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-3962
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Succes... Read more
Affected Products : nessus- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4348
Cross-site scripting (XSS) vulnerability in index.php in Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to inject arbitrary web script or HTML via the topic parameter in a topic action, a different vector than CVE-2006-2146.... Read more
Affected Products : hb-ns- Published: Dec. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4518
Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via an inserted node.... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0042
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIF... Read more
- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4521
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report p... Read more
Affected Products : birt- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4475
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4339
Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted From address, which is not properly handled when indexing messages.... Read more
Affected Products : hypermail- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4387
The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web scrip... Read more
- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4534
Open redirect vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025