Latest CVE Feed
-
4.3
MEDIUMCVE-2012-4490
Multiple cross-site scripting (XSS) vulnerabilities in the Excluded Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) user name or (2) email address.... Read more
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1742
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1... Read more
Affected Products : bugzilla- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5757
Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : rational_clearquest- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-2479
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a cra... Read more
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-13405
The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation on the 'awp_ip_deny' page. This makes it possible for unauthenti... Read more
Affected Products : apptivo_business_site_crm- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2013-1671
Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.... Read more
Affected Products : firefox- Published: May. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5744
Multiple cross-site scripting (XSS) vulnerabilities in the guest portal in Cisco Identity Services Engine (ISE) Software allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCud11139 and CSCug02904.... Read more
Affected Products : identity_services_engine_software- Published: Aug. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-21499
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms o... Read more
Affected Products : caddy-security- Published: Feb. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5702
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) com... Read more
Affected Products : dotproject- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-21665
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. ... Read more
Affected Products : e-commerce_framework- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3973
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter us... Read more
Affected Products : drupal- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2017-13852
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbit... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2012-5665
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.... Read more
- Published: Jan. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4596
Directory traversal vulnerability in McAfee Email Gateway (MEG) 7.0.0 and 7.0.1 allows remote authenticated users to bypass intended access restrictions and download arbitrary files via a crafted URL.... Read more
Affected Products : email_gateway- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4532
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. NOTE: some of... Read more
Affected Products : joomla\!- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1759
Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field.... Read more
Affected Products : responsive_logo_slideshow- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5672
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file wit... Read more
- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0575
Unspecified vulnerability in the Oracle Learning Management component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to OTA Self Service.... Read more
Affected Products : e-business_suite- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4580
Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote attackers to inject arbitrary web script or HTML via vectors re... Read more
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1743
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during... Read more
Affected Products : bugzilla- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025