Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10690
The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.4 via the 'SHORTCODE_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it poss... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
4.3
MEDIUMCVE-2015-2223
Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1) Argume... Read more
- Published: Apr. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1656
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and ... Read more
Affected Products : spree- Published: Mar. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-37176
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). The femap.exe application lacks proper validation of user-supplied data when parsing modfem files. This could result in an out of bounds... Read more
Affected Products : simcenter_femap- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2068
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/... Read more
Affected Products : magmi- Published: Feb. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-2485
Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : logicampus- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-5485
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" param... Read more
Affected Products : eventbrite_tickets- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2064
Cross-site scripting (XSS) vulnerability in theme/views_lang_switch.theme.inc in the Views Language Switcher module before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-4375
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity... Read more
Affected Products : ctools- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-6066
The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site... Read more
Affected Products : wp_custom_widget_area- Published: Jan. 15, 2024
- Modified: May. 12, 2025
-
4.3
MEDIUMCVE-2015-4292
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818.... Read more
- Published: Aug. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2181
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbasedir parameter.... Read more
Affected Products : campsite- Published: Jun. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2167
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.... Read more
Affected Products : plague_news_system- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-5246
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluat... Read more
Affected Products : secure_file_transfer- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2012-2899
Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors involvi... Read more
- Published: Jan. 05, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2780
Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (... Read more
Affected Products : 68_classifieds- Published: Aug. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2914
Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : captcha- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3301
Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and... Read more
Affected Products : lotus_domino- Published: Aug. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-2483
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.... Read more
Affected Products : business_objects_business_intelligence_platform businessobjects_business_intelligence- Published: Nov. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2177
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors related to... Read more
Affected Products : cognos_business_intelligence- Published: Mar. 05, 2013
- Modified: Apr. 11, 2025