Latest CVE Feed
-
4.3
MEDIUMCVE-2023-25030
Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.... Read more
Affected Products : buy_me_a_coffee- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-11054
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected w... Read more
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1669
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Sear... Read more
- Published: Sep. 10, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1237
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.... Read more
Affected Products : wwwboard- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-23848
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturin... Read more
Affected Products : synopsys_coverity- Published: Feb. 15, 2023
- Modified: Mar. 18, 2025
-
4.3
MEDIUMCVE-2006-4358
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web script or HTML via the read parameter.... Read more
Affected Products : diesel_pay- Published: Aug. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-2565
Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Create Item Instance.... Read more
Affected Products : e-business_suite- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2532
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability."... Read more
Affected Products : lync_server- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2003-1025
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "... Read more
Affected Products : internet_explorer- Published: Jan. 20, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1397
Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl.... Read more
Affected Products : usemodwiki- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-22945
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.... Read more
- Published: Jan. 11, 2023
- Modified: Apr. 07, 2025
-
4.3
MEDIUMCVE-2023-22938
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.... Read more
- Published: Feb. 14, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1586
Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.... Read more
Affected Products : webexpert- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-15733
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.... Read more
Affected Products : gitlab- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-0046
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.... Read more
Affected Products : snapstream_pvs- Published: Feb. 03, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-8727
A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting a malicious website may lead to address bar spoofing.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2826
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information d... Read more
- Published: Apr. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-19575
GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.... Read more
Affected Products : gitlab- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-28336
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.... Read more
- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1544
Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.... Read more
Affected Products : jspwiki- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025