Latest CVE Feed
-
4.3
MEDIUMCVE-2013-4703
Cross-site scripting (XSS) vulnerability in the top-page customization feature in Cybozu Office before 9.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : office- Published: Sep. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3843
Cross-site scripting (XSS) vulnerability in the registration page in e107, probably 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : e107- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3831
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script or HTML via multiple URLs in an img tag.... Read more
Affected Products : decoda- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3837
Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email_address, (3) password, (4) password_v... Read more
Affected Products : baby_gekko- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3842
Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.... Read more
Affected Products : directadmin- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2706
Cross-site scripting (XSS) vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to user registration.... Read more
- Published: Jun. 27, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-8732
Cross-site scripting (XSS) vulnerability in phpMemcachedAdmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : phpmemcachedadmin- Published: Nov. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2598
Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote attackers to cause a denial of service (agent outage) via crafted input.... Read more
Affected Products : wincc- Published: Jun. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2631
Cross-site scripting (XSS) vulnerability in WEBLOGIC @WEB ShoppingCart before 1.5.2.0, and @WEB ShoppingCart T 1.5.0.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2021
Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0340
Cross-site scripting (XSS) vulnerability in the management interface on the Cisco IronPort Encryption Appliance with software before 6.5.3 allows remote attackers to inject arbitrary web script or HTML via the header parameter to the default URI under adm... Read more
Affected Products : ironport_encryption_appliance- Published: Feb. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1333
Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the bulletin board system."... Read more
- Published: Jun. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1021
Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.... Read more
Affected Products : 4images- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1019
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Enterprise 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) XWiki.XWikiComments_comment parameter to xwiki/bin/commentadd/Main/WebHome, (2) XWiki.XWikiUsers_0_compan... Read more
Affected Products : xwiki_enterprise- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1018
Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter.... Read more
- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1930
Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers... Read more
Affected Products : cyber_recruiter- Published: Feb. 10, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1931
The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related inf... Read more
Affected Products : cyber_recruiter- Published: Feb. 10, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10331
A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : electricflow- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-0390
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.... Read more
Affected Products : diagnostics_agent- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-1003036
A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM age... Read more
Affected Products : azure_vm_agents- Published: Mar. 08, 2019
- Modified: Nov. 21, 2024