Latest CVE Feed
-
4.3
MEDIUMCVE-2009-2966
avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.... Read more
- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-6916
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.... Read more
Affected Products : bigtree_cms- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2007-4483
Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).... Read more
Affected Products : wordpressclassic- Published: Aug. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-50457
An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.... Read more
Affected Products : zammad- Published: Dec. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-2710
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is... Read more
Affected Products : joomla\!- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-32239
Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin – GetSocial.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Share Buttons & Analytics Plugin – GetSocial.io: fr... Read more
Affected Products : social_share_buttons_\&_analytics- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2009-0860
Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.... Read more
Affected Products : netmri- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10189
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.... Read more
Affected Products : moodle- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3367
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : web_wiz_rich_text_editor- Published: Jul. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3678
Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway before 1.4.2.197 allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more
Affected Products : freeway- Published: Aug. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-1602
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.... Read more
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-4127
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-regi... Read more
Affected Products : church_admin- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0834
Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 8.0.0 and 8.1.1 allows remote attackers to affect integrity via unknown vectors related to Globalization - Automotive.... Read more
Affected Products : siebel_crm- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2761
Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web site, related to GetWidget methods.... Read more
Affected Products : chrome- Published: Jul. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-15432
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An att... Read more
Affected Products : prime_infrastructure- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4507
Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspecified user input fields.... Read more
Affected Products : dev_hound- Published: Dec. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-2356
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.... Read more
Affected Products : elms_pro- Published: Jun. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-1935
Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.... Read more
Affected Products : campus_pipeline- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-8667
Cross-site scripting (XSS) vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : hana_web-based_development_workbench- Published: Nov. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-2418
Unspecified vulnerability in the Oracle Territory Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025