Latest CVE Feed
-
4.3
MEDIUMCVE-2013-6904
Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-4496
Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.... Read more
Affected Products : iwebnegar- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3429
Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies v... Read more
Affected Products : mailsite_express- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-0623
The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to missing or incorrect nonce validation on the vbp_clear_patterns_cache() function. This makes it possible ... Read more
Affected Products : vk_block_patterns- Published: Jan. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0870
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rc... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-3837
Cross-site scripting (XSS) vulnerability in the search module in sCssBoard 1.2 and 1.12, and earlier versions, allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.... Read more
Affected Products : scssboard- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-8992
Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl allows remote attackers to inject arbitrary web script or HTML via the callback parameter.... Read more
Affected Products : modx_revolution- Published: Dec. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-3103
Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.... Read more
Affected Products : bitweaver- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-0541
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.... Read more
Affected Products : simple_forum- Published: Feb. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-10050
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level acce... Read more
Affected Products : elementor_-_header\,_footer_\&_blocks_template elementor_header_\&_footer_builder- Published: Oct. 24, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2014-2002
Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : c-board_moyuku- Published: Jun. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0893
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web sc... Read more
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4288
The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-m... Read more
Affected Products : content_security_management_appliance web_security_appliance email_security_appliance- Published: Jul. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4547
Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory con... Read more
Affected Products : unreal_commander- Published: Aug. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-1027
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account modul... Read more
Affected Products : php-nuke- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1023
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr paramet... Read more
Affected Products : php-nuke- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-4268
Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST r... Read more
Affected Products : identity_services_engine_software- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-3109
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/ph... Read more
Affected Products : call_manager- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0901
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.... Read more
Affected Products : nukebookmarks- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1245
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : mediawiki- Published: May. 02, 2005
- Modified: Apr. 03, 2025