Latest CVE Feed
-
4.3
MEDIUMCVE-2022-45210
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.... Read more
Affected Products : jeecg_boot- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
4.3
MEDIUMCVE-2018-21095
Certain NETGEAR devices are affected by stored XSS. This affects SRR60 before 2.2.1.210 and SRS60 before 2.2.1.210.... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6418
The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake ke... Read more
- Published: Dec. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-34115
Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.... Read more
Affected Products : meeting_sdk- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3509
Cross-site scripting (XSS) vulnerability in admin/admin_index.php in CJ Dynamic Poll PRO 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : cj_dynamic_poll- Published: Oct. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-2180
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors.... Read more
Affected Products : appgoat- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2019-16698
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a new... Read more
Affected Products : direct_mail- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1059
Use-after-free vulnerability in WebCore in WebKit before r77705, as used in Google Chrome before 11.0.672.2 and other products, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impac... Read more
Affected Products : chrome- Published: Feb. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3539
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.... Read more
Affected Products : ultra_classifieds_pro- Published: Oct. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2043
Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary). NOTE: some of these details are ob... Read more
Affected Products : datatrack_system- Published: May. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-4763
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting t... Read more
Affected Products : sterling_file_gateway- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0325
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.... Read more
Affected Products : ninja_blog- Published: Jan. 29, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-27940
This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.... Read more
Affected Products : apple_tv- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-7320
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified v... Read more
Affected Products : appointment_booking_calendar- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-5114
Multiple cross-site scripting (XSS) vulnerabilities in the Authoritative DNS - DNS Zones page in Barracuda Link Balancer 330 Firmware 1.3.2.005 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) zoneid or (2) scope param... Read more
- Published: Aug. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5023
Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.... Read more
Affected Products : pligg_cms- Published: Dec. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-1068
The Download Read More Excerpt Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on the read_more_excerpt_link_menu_options() function. This ... Read more
Affected Products : read_more_excerpt_link- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4589
Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter.... Read more
- Published: Jan. 07, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1854
Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message. NOTE: the... Read more
Affected Products : pay_per_watch_\&_bid_auktions_system- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5707
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604.... Read more
Affected Products : coursemill_learning_management_system- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025