Latest CVE Feed
-
4.3
MEDIUMCVE-2007-3577
PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function expressi... Read more
Affected Products : phpids- Published: Jul. 05, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3579
PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.... Read more
Affected Products : phpids- Published: Jul. 05, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3623
Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the E... Read more
- Published: Jul. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3406
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) s... Read more
- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4981
Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a docu... Read more
Affected Products : obedit- Published: Sep. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3396
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.... Read more
Affected Products : kf_web_server- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3366
Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unk... Read more
Affected Products : cpanel- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3635
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2.1 for Squirrelmail might allow "local authenticated users" to inject certain commands via unspecified vectors. NOTE: this might overlap CVE-2005-1924, CVE-2006-4169, or CVE-2007-3634.... Read more
- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3426
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
Affected Products : phptraffica- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3645
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extensi... Read more
- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-22563
Cross-Site Request Forgery (CSRF) vulnerability in Faaiq Pretty Url allows Cross Site Request Forgery.This issue affects Pretty Url: from n/a through 1.5.4.... Read more
Affected Products : pretty_url- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-39472
Cross-Site Request Forgery (CSRF) vulnerability in WPWeb WooCommerce Social Login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a before 2.8.3.... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-0593
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read ... Read more
- Published: Feb. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0684
Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter.... Read more
Affected Products : itechclassifieds- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-12249
The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attack... Read more
Affected Products : gs_insever_portfolio- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-0617
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the gue... Read more
Affected Products : dmsguestbook- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0605
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id pa... Read more
Affected Products : astrosoft_helpdesk- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-4310
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI.... Read more
Affected Products : firefox- Published: Aug. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-0622
Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter.... Read more
Affected Products : raidenhttpd- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-7095
On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being ter... Read more
Affected Products : eos- Published: Jan. 10, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Denial of Service