Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2453
Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : networkactiv_web_server- Published: Aug. 04, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-47593
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2023-43502
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to delete Failure Causes.... Read more
Affected Products : build_failure_analyzer- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-0407
Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.... Read more
Affected Products : openconf- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-24940
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives... Read more
Affected Products : intellij_idea- Published: Feb. 06, 2024
- Modified: May. 15, 2025
-
4.3
MEDIUMCVE-2005-3285
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.... Read more
Affected Products : comersus_backoffice_plus- Published: Oct. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-20227
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk ro... Read more
- Published: Mar. 26, 2025
- Modified: Jul. 21, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2023-33947
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition f... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4528
Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) recherche parameter in recherchemembre.php and the (2) email parameter in test.php.... Read more
Affected Products : membrepass- Published: Sep. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-37890
Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Sup... Read more
- Published: Nov. 30, 2023
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2024-53245
In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read acc... Read more
- Published: Dec. 10, 2024
- Modified: Mar. 06, 2025
-
4.3
MEDIUMCVE-2005-3544
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : xmb- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3742
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.... Read more
Affected Products : advanced_poll- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2901
Multiple Cross-site scripting (XSS) vulnerabilities in CjWeb2Mail 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message, or (3) ip parameter to thankyou.php or (4) emsg parameter to web2mail.php.... Read more
Affected Products : cjweb2mail- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-54004
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.... Read more
Affected Products : filesystem_list_parameter- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
4.3
MEDIUMCVE-2024-54038
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low... Read more
Affected Products : connect- Published: Dec. 10, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2024-23273
This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.... Read more
- Published: Mar. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3403
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) th... Read more
Affected Products : atutor- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2899
Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter.... Read more
Affected Products : cj_tag_board- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-23243
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app may be able to read sensitive location information.... Read more
- Published: Mar. 05, 2024
- Modified: Dec. 05, 2024