Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3818
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parame... Read more
Affected Products : vtiger_crm- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3866
Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.... Read more
Affected Products : searchfeed_search_engine- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3841
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.... Read more
Affected Products : kplaylist- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3851
Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.... Read more
Affected Products : oasys_lite- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3867
Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.... Read more
Affected Products : revenuepilot_search_engine_script- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-37945
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.... Read more
Affected Products : saml_single_sign_on- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3908
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.... Read more
Affected Products : amazon_shop- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3894
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the Queu... Read more
Affected Products : otrs- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4053
Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html.... Read more
Affected Products : cowiki- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3742
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.... Read more
Affected Products : advanced_poll- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3971
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.... Read more
- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-1766
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.... Read more
Affected Products : business_process_manager- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3366
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack... Read more
Affected Products : multiparcels_shipping_for_woocommerce- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-8784
Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some para... Read more
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1773
IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed. IBM X-Force ID: 148691.... Read more
Affected Products : datacap- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4004
The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use ... Read more
Affected Products : donation_button- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
4.3
MEDIUMCVE-2023-2563
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes... Read more
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-29192
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.... Read more
Affected Products : silverwaregames- Published: Apr. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-45854
An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were... Read more
Affected Products : nwa110ax_firmware nwa210ax_firmware wax510d_firmware wax610d_firmware wax630s_firmware wax650s_firmware nwa110ax nwa210ax wax510d wax610d +2 more products- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1555
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.... Read more
Affected Products : api_connect- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025