Latest CVE Feed
-
4.3
MEDIUMCVE-2012-4437
Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.... Read more
Affected Products : smarty- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-6225
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normally protected configuration script.... Read more
Affected Products : email_encryption_gateway- Published: Mar. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-7071
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.... Read more
Affected Products : network_function_virtualization_director- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2129
Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action.... Read more
Affected Products : dokuwiki- Published: Aug. 27, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0005
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.... Read more
- Published: Jan. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2872
Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-0932
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Serv... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0892
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0998.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2605
Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatbox, probably involving the ctext parameter to send.php.... Read more
Affected Products : dschat- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-3585
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link. ... Read more
- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2634
Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field.... Read more
Affected Products : seditio- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-3577
Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF. ... Read more
- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2360
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.... Read more
Affected Products : passwd- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2003-0442
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-8530
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8512.... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4671
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly r... Read more
- Published: Jul. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2403
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.... Read more
Affected Products : wordpress- Published: Apr. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-4907
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.... Read more
- Published: Jul. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-5108
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to th... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2618
Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not ... Read more
Affected Products : webhost_directory- Published: May. 26, 2006
- Modified: Apr. 03, 2025