Latest CVE Feed
-
4.3
MEDIUMCVE-2002-1526
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.... Read more
Affected Products : emu_webmail- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4870
Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the... Read more
Affected Products : db2- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-46708
Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.... Read more
Affected Products : ddk- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2018-11784
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the ... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2002-1829
Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or ... Read more
Affected Products : openbb- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-2129
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.... Read more
Affected Products : w-agora- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5625
Cross-site scripting (XSS) vulnerability in filename.asp in ASP Site Search SearchSimon Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.... Read more
Affected Products : asp_site_search_searchsimon_lite- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1723
CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an ope... Read more
- Published: Aug. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0855
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_application_server- Published: Mar. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-21834
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workflow, Approval, Work Force Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privi... Read more
Affected Products : self-service_human_resources- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5683
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Oct. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1690
Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.... Read more
- Published: Apr. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2032
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm ... Read more
Affected Products : resin- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-11802
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and ... Read more
Affected Products : solr- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-21997
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network acces... Read more
Affected Products : user_management- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1712
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potent... Read more
- Published: Apr. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1897
Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerab... Read more
Affected Products : forefront_unified_access_gateway- Published: Oct. 12, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1726
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : sitescope- Published: May. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-5703
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. T... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jul. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-37147
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade... Read more
Affected Products : glpi- Published: Jul. 10, 2024
- Modified: Jan. 07, 2025