Latest CVE Feed
-
4.3
MEDIUMCVE-2021-22258
The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34147
Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4239
Cross-site scripting (XSS) vulnerability in Search/DisplayResults.php in PHP JackKnife 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via URL-encoded values in the sKeywords parameter.... Read more
Affected Products : php_jackknife- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0217
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error ... Read more
Affected Products : ultimate_auction- Published: Jan. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3085
Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.... Read more
Affected Products : rss_syndicator_module- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-38058
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35. ... Read more
Affected Products : otrs- Published: Jul. 24, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4236
Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters.... Read more
Affected Products : ckgold_shopping_cart- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3047
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-36845
An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.... Read more
Affected Products : libmodbus- Published: May. 31, 2024
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2005-4166
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.... Read more
Affected Products : duportal_pro- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4410
Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter.... Read more
Affected Products : nqcontent- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3025
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.p... Read more
Affected Products : vbulletin- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-22890
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the... Read more
Affected Products : fedora debian_linux curl fabric_operating_system hci_management_node solidfire libcurl sinec_infrastructure_network_services hci_storage_node communications_billing_and_revenue_management +2 more products- Published: Apr. 01, 2021
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2005-4205
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : locazolist_classifieds- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4150
Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors.... Read more
Affected Products : cleverpath_portal- Published: Dec. 10, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0818
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.... Read more
Affected Products : punbb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4235
Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.... Read more
Affected Products : whmcompletesolution- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4167
Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.... Read more
Affected Products : efiction- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-36050
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.... Read more
Affected Products :- Published: May. 18, 2024
- Modified: Jun. 27, 2025
-
4.3
MEDIUMCVE-2005-4262
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE... Read more
Affected Products : envolution- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025