Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13208
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more
Affected Products : wp_google_map- Published: Feb. 15, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2010-4971
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.... Read more
- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4966
Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search action.... Read more
Affected Products : netvolution- Published: Oct. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1564
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that ... Read more
- Published: Sep. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-0987
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, ... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4514
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third par... Read more
Affected Products : dotnetnuke- Published: Dec. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4453
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container.... Read more
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0613
Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to (1) wf_status.htm and (2) wf_topicfs.htm in RoboHTML/Wi... Read more
- Published: May. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4491
Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.... Read more
Affected Products : chrome- Published: Dec. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-1192
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwis... Read more
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1218
Cross-site scripting (XSS) vulnerability in the mm_forum extension 1.8.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-5045
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.... Read more
Affected Products : smart_asp_survey- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4483
Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.... Read more
Affected Products : chrome- Published: Dec. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-27218
Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.... Read more
Affected Products : incapptic_connect_uploader- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4447
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2453
Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which i... Read more
Affected Products : diskstation_manager dsm disk_station_ds1010\+ disk_station_ds109 disk_station_ds110\+ disk_station_ds110j disk_station_ds209 disk_station_ds210\+ disk_station_ds210j disk_station_ds409slim +4 more products- Published: Sep. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1803
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validati... Read more
Affected Products : embedpress- Published: May. 23, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2010-4475
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1747
Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via craft... Read more
Affected Products : chrome- Published: May. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-1059
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'.... Read more
- Published: May. 21, 2020
- Modified: Nov. 21, 2024