Latest CVE Feed
-
4.3
MEDIUMCVE-2007-4037
Guidance Software EnCase allows user-assisted attackers to trigger a buffer over-read and application crash via a malformed NTFS filesystem containing a modified FILE record with a certain large offset. NOTE: the vendor disputes the significance of this i... Read more
Affected Products : encase- Published: Jul. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2908
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4048
Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : phpsysinfo- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4064
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated adm... Read more
Affected Products : drupal- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4058
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first argument to the StartProcess method.... Read more
Affected Products : vmware- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4089
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components.... Read more
Affected Products : vikingboard- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2887
Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.... Read more
Affected Products : web_icerik_yonetim_sistemi- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4081
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to inject arbitrary web script or HTML via vectors in (a) merchants/index.php, including the (1) id or (2) msg parameter in a programedit action... Read more
Affected Products : affiliate_network_pro- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-0516
Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.... Read more
Affected Products : gitlab- Published: Feb. 12, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-4075
Cross-site scripting (XSS) vulnerability in index.asp in Alisveris Sitesi Scripti allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search mod action. NOTE: the provenance of this information is unknown; the details ... Read more
Affected Products : alisveris_sitesi_script- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4088
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) f, (3) quote, and (4) act parameters to cp.php; the (5) u parameter to user.php; the (6) f parameter... Read more
Affected Products : vikingboard- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2885
The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument.... Read more
Affected Products : visual_database_tools_database_designer- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-1110
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2019-10452
Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.... Read more
Affected Products : view26_test-reporting- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4079
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid parameter ... Read more
Affected Products : sms_text_messaging_enterprise- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-3738
Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3733
Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10447
Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.... Read more
Affected Products : sofy.ai- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4724
Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.... Read more
Affected Products : tomcat- Published: Sep. 05, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-4906
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024