Latest CVE Feed
-
4.3
MEDIUMCVE-2014-2578
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : splunk- Published: Apr. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2157
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.... Read more
Affected Products : skytap_cloud_ci- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2538
Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.... Read more
Affected Products : rack-ssl- Published: Mar. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2536
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file c... Read more
- Published: Mar. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2589
Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.... Read more
Affected Products : nsa_2400- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2208
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.... Read more
Affected Products : slack_upload- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2542
Cross-site scripting (XSS) vulnerability in the Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, an... Read more
- Published: Apr. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2239
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.... Read more
Affected Products : parameterized_remote_trigger- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1292
ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be r... Read more
- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2586
Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web script or HTML via a crafted password.... Read more
Affected Products : cloud_single_sign_on- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3381
Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2939
Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inject arbitrary web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the taskId parameter to share/page/task-edit.... Read more
Affected Products : alfresco- Published: Jun. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2947
Cross-site scripting (XSS) vulnerability in Login.aspx in Bizagi BPM Suite before 10.3 allows remote attackers to inject arbitrary web script or HTML via the txtUsername parameter.... Read more
Affected Products : business_process_management_suite- Published: May. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3010
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script o... Read more
Affected Products : websphere_service_registry_and_repository- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2968
Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.... Read more
- Published: Jul. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3568
OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.... Read more
Affected Products : openssl- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3575
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation libreoffice openoffice- Published: Aug. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2963
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_mid... Read more
Affected Products : liferay_portal- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3004
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.... Read more
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2975
Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.... Read more
Affected Products : vx- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025