Latest CVE Feed
-
4.3
MEDIUMCVE-2024-12027
The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateFilter() and deleteFilter() functions in all versions up to, and including, 1.6.3. This makes it p... Read more
Affected Products : message_filter_for_contact_form_7- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.3
MEDIUMCVE-2010-5042
Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. NOTE: so... Read more
- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-5069
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overl... Read more
Affected Products : chrome- Published: Dec. 07, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4433
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.ph... Read more
Affected Products : isupport- Published: Dec. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2717
Cross-site scripting (XSS) vulnerability in manager/login.php in CruxSoftware CruxCMS 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the txtusername parameter.... Read more
Affected Products : cruxcms- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-5005
Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileCommentTextArea parameter. NOTE: the provenance of this information is unknown; ... Read more
Affected Products : photoz- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12201
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers,... Read more
Affected Products : hash_form- Published: Dec. 12, 2024
- Modified: Feb. 27, 2025
-
4.3
MEDIUMCVE-2020-15668
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.... Read more
Affected Products : firefox- Published: Oct. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12340
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider.php and widgets/tabs.php. This makes it possible for au... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
4.3
MEDIUMCVE-2021-23953
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-3987
Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : insight_control_virtual_machine_management- Published: Oct. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12206
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing or incorrect nonce validation on the stm_header_builder page. This makes it po... Read more
Affected Products : pearl_header_builder- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2010-2733
Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XS... Read more
Affected Products : forefront_unified_access_gateway- Published: Nov. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3289
Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : systems_insight_manager- Published: Oct. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3827
Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Nov. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3283
Open redirect vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : system_management_homepage- Published: Sep. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3911
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username (aka default_user_name) field or (2) the password field in a Users Login action to index.php,... Read more
Affected Products : vtiger_crm- Published: Nov. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2896
IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.... Read more
Affected Products : filenet_content_manager- Published: Jul. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4693
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.... Read more
Affected Products : coppermine_photo_gallery- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12244
An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prio... Read more
Affected Products : gitlab- Published: Apr. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization