Latest CVE Feed
-
4.3
MEDIUMCVE-2006-7187
Cross-site scripting (XSS) vulnerability in the show_recent_searches function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to inject arbitrary web script or HTML via the srch variable.... Read more
Affected Products : webapp- Published: Apr. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1395
Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an upper... Read more
Affected Products : phpmyadmin- Published: Mar. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-37968
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6300
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.... Read more
Affected Products : cutenews- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0939
Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripti... Read more
Affected Products : content_management_server- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0578
The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.... Read more
Affected Products : mpg123- Published: Jan. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7226
Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows conte... Read more
- Published: Dec. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-1627
The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : my_private_site- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39870
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-46628
Missing Authorization vulnerability in RedLettuce Plugins WP Word Count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Word Count: from n/a through 3.2.4.... Read more
Affected Products : wp_word_count- Published: Jan. 02, 2025
- Modified: Mar. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-5932
Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and po... Read more
Affected Products : fatwire_content_server- Published: Nov. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-56215
Missing Authorization vulnerability in Stephen Sherrard Member Directory and Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through 1.7.0.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
4.3
MEDIUMCVE-2023-45824
OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId hash. This vulnerability is fixed in 5.1.4.... Read more
Affected Products : oroplatform- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-7230
Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate the amount of memory needed for a compiled regular expression pattern when the (1) -x or (2) -i UTF-8 options change within the pattern, which allows context-dependen... Read more
Affected Products : pcre- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7209
Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to keywords results in the (1) main, (2) daily, (3) weekly, (4) monthly, (5) n... Read more
Affected Products : phptraffica- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0998
The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrate... Read more
- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-11908
The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.... Read more
Affected Products : tcp\/ip- Published: Jun. 17, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1238
Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.... Read more
Affected Products : office- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7245
Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.... Read more
Affected Products : monkey\'s_audio- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-48740
Missing Authorization vulnerability in Easy Social Feed Easy Social Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Feed: from n/a through 6.5.1.... Read more
Affected Products : easy_social_feed- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025