Latest CVE Feed
-
4.3
MEDIUMCVE-2014-4531
Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the n parameter.... Read more
Affected Products : game_tabs- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2004-0534
Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.... Read more
- Published: Sep. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-4580
Cross-site scripting (XSS) vulnerability in blipbot.ajax.php in the WP BlipBot plugin 3.0.9 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the BlipBotID parameter.... Read more
Affected Products : wp_blipbot- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1180
Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.... Read more
Affected Products : eventsentry- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4804
Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive u... Read more
Affected Products : curam_social_program_management- Published: Feb. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-1284
The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missin... Read more
Affected Products :- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2006-2989
Cross-site scripting (XSS) vulnerability in listpics.asp in ASP ListPics 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the info parameter.... Read more
Affected Products : listpics- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-7903
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.... Read more
Affected Products : dotclear- Published: Jan. 04, 2017
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1915
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attac... Read more
Affected Products : endpoint_manager_family- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1431
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos ... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-2034
Cross-site scripting (XSS) vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter to admin.php.... Read more
Affected Products : piwigo- Published: Feb. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2088
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : term_queue- Published: Feb. 26, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5088
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.... Read more
Affected Products : status2k- Published: Aug. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2246
The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the disclosure of contact information.... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2012-2637
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.... Read more
Affected Products : web_patio- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-1706
Uncontrolled array index in IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large value in a certain 32-bit field.... Read more
Affected Products : soliddb- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4340
Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a carriage return ("\r\n\r\n") argument to the window.open function.... Read more
Affected Products : chrome- Published: Sep. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4327
gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows use... Read more
Affected Products : windows_xp- Published: Sep. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-2026
IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.... Read more
Affected Products : financial_transaction_manager- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2918
Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.... Read more
Affected Products : chevereto- Published: May. 21, 2012
- Modified: Apr. 11, 2025