Latest CVE Feed
-
4.3
MEDIUMCVE-2007-5493
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.... Read more
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3003
details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant from another vulnerability, since this vector also produces... Read more
Affected Products : easy_ad-manager- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5242
Unspecified vulnerability in (1) SYS$EI1000.EXE and (2) SYS$EI1000_MON.EXE in HP OpenVMS 8.3 and earlier allows remote attackers to cause a denial of service (machine crash) via an "oversize" packet, which is not properly discarded if "the device has no r... Read more
- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2004-1790
Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more
Affected Products : full_rate_adsl_router- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-6772
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by ... Read more
Affected Products : elastic_services_controller- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2006-3087
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m parameter in (a) common/galleries.asp; (6) aid, (7) ... Read more
Affected Products : ezgallery- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-27384
Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.... Read more
Affected Products : garoon- Published: May. 23, 2023
- Modified: Jan. 17, 2025
-
4.3
MEDIUMCVE-2018-11342
A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a file on the system to create folders via the dest_folder parameter.... Read more
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0533
Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this informatio... Read more
Affected Products : ez_reminder- Published: Feb. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-0393
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.... Read more
Affected Products : quality_management- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0830
Cross-site scripting (XSS) vulnerability in QuoteBook allows remote attackers to inject arbitrary web script or HTML via the (1) QuoteName and (2) QuoteText parameters to quotesadd.php. NOTE: the provenance of this information is unknown; the details are... Read more
Affected Products : quotebook- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3303
Multiple cross-site scripting (XSS) vulnerabilities in pm.php in DeluxeBB 1.07 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) to parameters.... Read more
Affected Products : deluxebb- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5111
A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (crash) via a string argument to the AddString method.... Read more
Affected Products : ebcrypt- Published: Sep. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10187
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.... Read more
Affected Products : moodle- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0875
Unspecified vulnerability in the Life Sciences - Oracle Thesaurus Management System component in Oracle Industry Product Suite 4.5.2, 4.6, and 4.6.1 allows remote attackers to affect integrity, related to TMS Browser.... Read more
Affected Products : industry_product_suite- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-1561
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulner... Read more
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2880
Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp.... Read more
Affected Products : digirez- Published: May. 29, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-2809
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage & Navigation). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticat... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2615
Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions SitePal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_admin_login.asp, (2) z_forgot.asp, and possibly unspecified other componen... Read more
Affected Products : sitepal- Published: Jul. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-5315
Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web script or HTML via the message parameter to (1) messages_viewer.php, (2) home.php, or (3) history.php.... Read more
Affected Products : php_ireport- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025