Latest CVE Feed
-
4.3
MEDIUMCVE-2009-2480
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-5743
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.... Read more
Affected Products : tcexam- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-14369
RSA Archer GRC Platform prior to 6.2.0.5 is affected by a privilege escalation vulnerability. A low privileged RSA Archer user may potentially exploit this vulnerability to elevate their privileges and export certain application records.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-1476
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to received trackbacks.... Read more
- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5920
The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.... Read more
Affected Products : itunes- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-7364
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 ... Read more
Affected Products : uc_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-3942
Multiple cross-site scripting (XSS) vulnerabilities in the web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5670
Cross-site scripting (XSS) vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : enisys_gw- Published: Oct. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3440
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.... Read more
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3106
Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1)... Read more
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2003-1543
Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.... Read more
Affected Products : java_http_server- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1480
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.... Read more
- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-3781
Cross-site scripting (XSS) vulnerability in Quick Look in Apple OS X before 10.10.5 allows remote attackers to inject arbitrary web script or HTML via a previously visited web site that is rendered during a Quick Look search.... Read more
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5654
Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dojo- Published: Oct. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2198
Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.... Read more
- Published: Aug. 04, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-3725
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.... Read more
Affected Products : iphone_os- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3720
The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.... Read more
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1880
Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : fortios- Published: May. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-7268
Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name ... Read more
Affected Products : email_gateway- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5943
SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app.... Read more
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025