Latest CVE Feed
-
4.3
MEDIUMCVE-2012-6632
Multiple cross-site scripting (XSS) vulnerabilities in Vessio NetBill 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) file title to accounts/admin/index.php or (3) comment parameter in the support page to acc... Read more
Affected Products : netbill- Published: Jan. 16, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1375
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all versions up to, and including, 5.9.5. This makes it possible for unauthenticated attackers to update ... Read more
Affected Products :- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-6542
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.... Read more
- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-5035
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended m... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-100037
Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to archives/.... Read more
Affected Products : storytlr- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-1003010
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.... Read more
- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4354
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : webglimpse- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-0895
Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.... Read more
- Published: Jan. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-21436
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.... Read more
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5930
Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4844
Cross-site scripting (XSS) vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : lotus_domino- Published: Feb. 27, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-5076
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in protected/views/admin/formEditor.php; the (2) importId parameter in protected... Read more
Affected Products : x2crm- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-21927
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network ac... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0995
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 allows remote attackers to affect integrity via unknown vectors.... Read more
- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6157
Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.... Read more
Affected Products : simplegallery- Published: Nov. 29, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3649
Cross-site scripting (XSS) vulnerability in KENT-WEB CLIP-MAIL before 3.4, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an unspecified form field.... Read more
- Published: Jun. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6642
Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter to view_channel.php. NOTE: the provenance of this information is unknown; the details are obtained solely fro... Read more
Affected Products : clipbucket- Published: Apr. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-7369
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 ... Read more
Affected Products : yandex_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify... Read more
Affected Products : manageengine_servicedesk_plus- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6635
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the src parameter in the search action to index.php.... Read more
Affected Products : exponent_cms- Published: Oct. 26, 2014
- Modified: Apr. 12, 2025