Latest CVE Feed
-
4.3
MEDIUMCVE-2024-47780
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowe... Read more
Affected Products : typo3- Published: Oct. 08, 2024
- Modified: Sep. 03, 2025
-
4.3
MEDIUMCVE-2013-4833
Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : service_manager- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-15696
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.... Read more
Affected Products : data_master- Published: Aug. 27, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5319
Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/DeleteUs... Read more
- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-25622
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers handler allows users to modify the response headers being sent by h2o. The configuration file of h2o has scopes, and the inner scopes ... Read more
Affected Products : h2o- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2013-4815
Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-2778
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java ... Read more
Affected Products : ubuntu_linux debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight oncommand_workflow_automation jdk jre e-series_santricity_os_controller +10 more products- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4519
Multiple cross-site scripting (XSS) vulnerabilities in Review Board 1.6.x before 1.6.21 and 1.7.x before 1.7.17 allow remote attackers to inject arbitrary web script or HTML via the (1) Branch field or (2) caption of an uploaded file.... Read more
Affected Products : review_board- Published: Nov. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4499
Cross-site scripting (XSS) vulnerability in the Bean module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via the bean title.... Read more
Affected Products : bean- Published: Feb. 14, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4556
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.... Read more
Affected Products : spip- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2270
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5421
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynami... Read more
Affected Products : security_access_manager_for_enterprise_single_sign-on- Published: Dec. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4411
Review Board: URL processing gives unauthorized users access to review lists... Read more
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4453
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.... Read more
Affected Products : ldap_account_manager- Published: Nov. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4399
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by reg... Read more
Affected Products : libvirt- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-0995
Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.... Read more
- Published: Feb. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3690
Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function i... Read more
- Published: Oct. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5389
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK2X.... Read more
Affected Products : lotus_domino- Published: Oct. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2283
epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application cras... Read more
Affected Products : wireshark- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-27628
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.... Read more
Affected Products : teamcity- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024