Latest CVE Feed
-
4.3
MEDIUMCVE-2024-2155
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be in... Read more
- Published: Mar. 04, 2024
- Modified: Apr. 22, 2025
-
4.3
MEDIUMCVE-2013-3736
Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file.... Read more
- Published: May. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-25783
Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1449
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMajor field. NOTE: this may later be SPLIT into multiple CVEs if additional information is pu... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-5272
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the play... Read more
- Published: May. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0886
Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the "City/Region" field (mesto variable). NOTE: the provenance of this information is unknown; th... Read more
Affected Products : dev_web_management_system- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-5270
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication... Read more
- Published: May. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4083
The Easy Restaurant Table Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthent... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-45349
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. ... Read more
Affected Products : betheme- Published: Mar. 25, 2024
- Modified: Jan. 31, 2025
-
4.3
MEDIUMCVE-2012-6510
Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PWRS or (2) Description field when posting a new vehicle; (3) news title when creating news; (4) N... Read more
Affected Products : car_portal- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5194
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than... Read more
- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10388
A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.... Read more
Affected Products : relution_enterprise_appstore_publisher- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0655
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- Published: Feb. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5500
Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuj23320, CSCuj23324, CSCuj23333, and CSCuj23338... Read more
Affected Products : mediasense- Published: Sep. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6037
Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.... Read more
Affected Products : secure_mail_gateway- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4942
Multiple cross-site scripting (XSS) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to inject arbitrary web script or HTML via an arbitrary text field.... Read more
- Published: Nov. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3560
Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : kshop_module- Published: Aug. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-48285
Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage allows Cross Site Request Forgery. This issue affects Falang multilanguage: from n/a through 1.3.61.... Read more
Affected Products : falang- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-4541
Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : matomo- Published: Nov. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-42015
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disc... Read more
Affected Products : urbancode_deploy- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024