Latest CVE Feed
-
4.3
MEDIUMCVE-2008-6699
Cross-site scripting (XSS) vulnerability in Resource Library (tjs_reslib) 0.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
- Published: Apr. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-1656
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and ... Read more
Affected Products : spree- Published: Mar. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0366
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.... Read more
Affected Products : security_privileged_identity_manager- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1037
Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an arbitrar... Read more
- Published: Feb. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-21395
Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the time th... Read more
Affected Products : magento- Published: Jan. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32084
Cross-Site Request Forgery (CSRF) vulnerability in Gold Plugins Before And After.This issue affects Before And After: from n/a through 3.9. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-5207
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.... Read more
- Published: Oct. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2583
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.... Read more
Affected Products : mini_mail_dashboard_widget- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-6996
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML and web script via the (1) title and (2) newspost parameters to (a) newsadd.php, and the (3) name, title, and (4) comment parameters t... Read more
Affected Products : warforge.news- Published: Feb. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2492
Unspecified vulnerability in the Oracle Agile Product Collaboration component in Oracle Supply Chain Products Suite 9.3.3 allows remote attackers to affect integrity via unknown vectors related to Web client (PC).... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-2887
IBM Lotus Symphony 3 before FP3 on Linux allows remote attackers to cause a denial of service (application crash) via a certain sample document.... Read more
- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-4687
IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should not have access to. IBM X-Force ID: 186679.... Read more
- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2207
Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.... Read more
Affected Products : maian_gallery- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6173
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script or HTML via the emailAddress parameter in a Send New Password action, a different vector than CVE-2007-605... Read more
Affected Products : liferay_enterprise_portal- Published: Nov. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-7277
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to saa.php, (2) username parameter to login.php, or (3) ke... Read more
Affected Products : aphpkb- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3800
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.... Read more
Affected Products : afcommerce_shopping_cart- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-2064
A vulnerability has been found in rahman SelectCours 1.0 and classified as problematic. Affected by this vulnerability is the function getCacheNames of the file CacheController.java of the component Template Handler. The manipulation of the argument fragm... Read more
Affected Products : selectcours- Published: Mar. 01, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2006-0924
Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added. NOTE: the provenance of this information is unknown; the details are ob... Read more
Affected Products : ical- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1430
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter ... Read more
Affected Products : hms- Published: Mar. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-7368
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id para... Read more
Affected Products : gnew- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025