Latest CVE Feed
-
4.3
MEDIUMCVE-2014-5147
Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.... Read more
Affected Products : xen- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-29977
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts... Read more
- Published: Aug. 01, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2014-5191
Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : ckeditor- Published: Aug. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5129
Cross-site scripting (XSS) vulnerability in Avolve Software ProjectDox 8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : projectdox- Published: Sep. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-2032
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
Affected Products : mysql mariadb oncommand_insight oncommand_workflow_automation snapcenter mysql_server- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5101
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9)... Read more
Affected Products : webid- Published: Jul. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5098
Cross-site scripting (XSS) vulnerability in the Search module before 1.2.2 in Jamroom allows remote attackers to inject arbitrary web script or HTML via the query string to search/results/.... Read more
Affected Products : search_module- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5076
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by t... Read more
Affected Products : labanquepostale- Published: Sep. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5105
Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) a_country parameter in a process action to affiliate_signup.php or (2) entry_country_id parameter in an edit... Read more
Affected Products : ol-commerce- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5113
Multiple cross-site scripting (XSS) vulnerabilities in test.php in Visualware MyConnection Server 9.7i allow remote attackers to inject arbitrary web script or HTML via the (1) testtype, (2) ver, (3) cm, (4) map, (5) lines, (6) pps, (7) bpp, (8) codec, (9... Read more
Affected Products : myconnection_server- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-36736
The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to missing or incorrect nonce validation on the export_json, import_json, and sta... Read more
Affected Products : cartflows- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5018
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related t... Read more
Affected Products : limesurvey- Published: Jul. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5103
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.... Read more
Affected Products : manageengine_eventlog_analyzer- Published: Jul. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4738
Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) user/ldap_user/check_dlg or (2) user/radius_user/c... Read more
Affected Products : fortiweb- Published: Jul. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-3322
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vu... Read more
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48234
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been ... Read more
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4737
Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to setup/index.php.... Read more
Affected Products : textpattern- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5566
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or ... Read more
- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4749
IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.... Read more
Affected Products : powervc- Published: Aug. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4751
Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Mobile 8.0.0.0, 8.0.0.1, and 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : security_access_manager_for_mobile- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025