Latest CVE Feed
-
4.3
MEDIUMCVE-2010-5303
Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorStri... Read more
Affected Products : timthumb- Published: Aug. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-14566
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability allows... Read more
Affected Products : primavera_portfolio_management- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-5302
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.... Read more
Affected Products : timthumb- Published: Aug. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-1399
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected s... Read more
Affected Products : unified_communications_manager- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-5284
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to mana... Read more
Affected Products : collabtive- Published: Nov. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-13792
PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.... Read more
Affected Products : playtube- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1846
The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedb... Read more
Affected Products : netweaver- Published: Apr. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-10981
GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.... Read more
Affected Products : gitlab- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4672
Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.... Read more
Affected Products : simple_image_editor- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1906
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year action.... Read more
Affected Products : cpcommerce- Published: Apr. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1850
Multiple cross-site scripting (XSS) vulnerabilities in login.php in Omnistar Interactive OSI Affiliate allow remote attackers to inject arbitrary web script or HTML via the (1) login, (2) profile, (3) profile2, and (4) ref parameters.... Read more
Affected Products : osiaffiliate- Published: Apr. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-4337
The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the aha_plugin_page() function. This makes it possible for unauthenticat... Read more
Affected Products : ahathat- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-54535
A path handling issue was addressed with improved logic. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An attacker with access to calendar data could also read reminders.... Read more
- Published: Jan. 15, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2008-1603
Cross-site scripting (XSS) vulnerability in GNB DesignForm before 3.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the email form.... Read more
Affected Products : designform- Published: Apr. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-10399
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attacke... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2008-1589
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites.... Read more
- Published: Jul. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-22729
Missing Authorization vulnerability in Infomaniak Staff VOD Infomaniak allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VOD Infomaniak: from n/a through 1.5.9.... Read more
Affected Products : vod_infomaniak- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1548
Multiple cross-site scripting (XSS) vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to inject arbitrary web script or HTML via the (1) UserName parameter to loginproc.asp... Read more
Affected Products : aeries_student_information_system- Published: Mar. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1387
ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.... Read more
Affected Products : clamav- Published: Apr. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5729
A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.... Read more
Affected Products : firefox- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024