Latest CVE Feed
-
4.3
MEDIUMCVE-2011-0217
Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3457
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in articles/a-primer-to-symphony-2s-defaul... Read more
- Published: Sep. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0842
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated... Read more
- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0654
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and t... Read more
- Published: Feb. 18, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15376
Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges ... Read more
Affected Products : fabric_operating_system- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0244
WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0746
Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the ... Read more
Affected Products : o2_dsl_router_classic- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-6490
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.... Read more
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0741
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.... Read more
Affected Products : evolution- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-5314
Cross-site scripting (XSS) vulnerability in controllers/home_controller.php in BEdita before 3.1 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter to news/index.... Read more
- Published: Jan. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-13270
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.... Read more
Affected Products : freelinking- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2010-5144
The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and mo... Read more
- Published: Aug. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15219
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.... Read more
Affected Products : itop- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0773
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : pivotx- Published: Feb. 04, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13288
Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.... Read more
Affected Products : monster_menus- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2010-5192
Cross-site scripting (XSS) vulnerability in the Java Management Console in Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote attackers to inject arbitrary web script or HTML ... Read more
Affected Products : sgos proxysg proxysg_sg210-10 proxysg_sg210-25 proxysg_sg210-5 proxysg_sg510-10 proxysg_sg510-20 proxysg_sg510-25 proxysg_sg510-5 proxysg_sg810-10 +6 more products- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3675
The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via c... Read more
Affected Products : ffmpeg- Published: Jun. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13271
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.... Read more
Affected Products : content_entity_clone- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2011-0274
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vec... Read more
- Published: Jan. 24, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-3474
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality via vectors related to Security.... Read more
Affected Products : business_intelligence_publisher- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025