Latest CVE Feed
-
4.3
MEDIUMCVE-2007-4212
Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing "<" instead of a ">" in (1) the onerror attribute of an IMG element, (2) the onload attribute... Read more
Affected Products : php-nuke- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4165
Cross-site scripting (XSS) vulnerability in index.php in the Blue Memories theme 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757 and CVE-2007-4014. NOTE: the ... Read more
Affected Products : blue_memories_theme- Published: Aug. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-0675
Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.... Read more
- Published: May. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4445
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Messag... Read more
Affected Products : hostapd- Published: Oct. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-21219
MapUrlToZone Security Feature Bypass Vulnerability... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows +5 more products- Published: Jan. 14, 2025
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2007-4195
Use-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain ext2fs files via a malformed ext2fs image.... Read more
- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10203
PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS.... Read more
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4142
Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server 7.5.1 before 20070731 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a crafted Sametime meeting.... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2071
Multiple cross-site scripting (XSS) vulnerabilities in Open-gorotto 2.0a 2006/02/08 edition, 2006/03/19 edition, and 2006/04/07 edition before 20070416 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) pub/mod... Read more
Affected Products : open-gorotto- Published: Apr. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4122
Unspecified vulnerability in Hitachi JP1/Cm2/Hierarchical Viewer (HV) 06-00 through 06-71-/B allows remote attackers to cause a denial of service (application stop and web interface outage) via certain "unexpected data."... Read more
Affected Products : jp1-cm2-hierarchical_viewer- Published: Aug. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-1010220
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c... Read more
Affected Products : tcpdump- Published: Jul. 22, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2061
Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : mailbee_webmail- Published: Apr. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4102
Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3 Beta allows remote attackers to inject arbitrary HTML and web script via a leading '"/></> sequence in the search string.... Read more
Affected Products : sblog- Published: Jul. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-39229
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s userna... Read more
Affected Products : grafana- Published: Oct. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4090
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to inc/lib/screen.php or (2) the title parameter to post.php. NOTE: vector 2 might overlap CVE-2006-628... Read more
Affected Products : vikingboard- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4079
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid parameter ... Read more
Affected Products : sms_text_messaging_enterprise- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1709
Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.... Read more
Affected Products : php- Published: Mar. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-4186
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4183
Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-1110
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization