Latest CVE Feed
-
4.3
MEDIUMCVE-2013-7258
Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "displaying group DN and entry data in group administration UI."... Read more
Affected Products : web2ldap- Published: Jan. 03, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0668
Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA Portal) 11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : wincc_tia_portal- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2909
Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field in ... Read more
Affected Products : viscacha- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0984
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain pas... Read more
- Published: Apr. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-36800
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected version... Read more
Affected Products : jira_service_management- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1636
Cross-site scripting (XSS) vulnerability in index.php in JV2 Quick Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the f parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from t... Read more
Affected Products : quick_gallery- Published: Apr. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5714
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authen... Read more
Affected Products : system_dashboard- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6601
Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2)... Read more
- Published: Dec. 15, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-48023
Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of their customer tickets using the Zammad API. This is now corrected in v5.3.1 so that only agents with write permissions may change tick... Read more
Affected Products : zammad- Published: Feb. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3730
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly... Read more
Affected Products : revize_cms- Published: Nov. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-1482
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.... Read more
Affected Products : cms_made_simple- Published: May. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-8422
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, cred... Read more
Affected Products : manageengine_remote_access_plus- Published: Jan. 31, 2020
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2022-40198
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.... Read more
Affected Products : terawallet- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2884
Cross-site scripting (XSS) vulnerability in events.php in Land Down Under (LDU) 801 and earlier allows remote attackers to inject arbitrary web script or HTML via the Description field in an event.... Read more
Affected Products : land_down_under- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4898
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.... Read more
Affected Products : rateme- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-22229
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs th... Read more
Affected Products : unity_operating_environment unity_xt_operating_environment unityvsa_operating_environment- Published: Jan. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1020
Multiple cross-site scripting (XSS) vulnerabilities in login.php in NexorONE Online Banking allow remote attackers to inject arbitrary web script or HTML via the (1) visitor_language parameter to register.php or (2) message parameter.... Read more
Affected Products : nexorone_online_banking_system- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3500
Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.... Read more
Affected Products : suggested_terms_module- Published: Aug. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1254
Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : segue- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-24905
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enab... Read more
- Published: May. 20, 2022
- Modified: Nov. 21, 2024