Latest CVE Feed
-
4.3
MEDIUMCVE-2015-4465
Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : zm_ajax_login_\&_register- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-36800
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected version... Read more
Affected Products : jira_service_management- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-9361
The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly obtain sensitive information by acces... Read more
Affected Products : logintoboggan- Published: Dec. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-37885
Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. ... Read more
Affected Products :- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6012
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it... Read more
Affected Products : cost_calculator_builder- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-2366
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.... Read more
Affected Products : sap_business_process_automation- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2963
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) module_bbcodeloader.php, (2) module_div.php, (3) module_email... Read more
Affected Products : invision_power_board- Published: May. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3948
Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-mani... Read more
Affected Products : iphone_os- Published: Jun. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3645
Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : orchard- Published: Jun. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1749
Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via the Address field.... Read more
Affected Products : php_address_book- Published: Apr. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-8286
Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishi... Read more
Affected Products : anti-virus free_anti-virus internet_security small_office_security total_security- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-7258
Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "displaying group DN and entry data in group administration UI."... Read more
Affected Products : web2ldap- Published: Jan. 03, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-100027
Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : wp_slimstat- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3995
Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.... Read more
Affected Products : djblets- Published: Jun. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-39121
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected v... Read more
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1873
Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary web script or HTML via a CSS property in the STYLE attribute of a DIV eleme... Read more
- Published: Apr. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-5176
Cross-site scripting (XSS) vulnerability in KENT-WEB ACCESS REPORT 5.02 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to tag embedding.... Read more
Affected Products : access_report- Published: Dec. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-1035
Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an "ATTACH;VALUE=URI:S=osumi" line in a .ics file, which tri... Read more
Affected Products : ical- Published: Jun. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1614
suPHP before 0.6.3 allows local users to gain privileges via (1) a race condition that involves multiple symlink changes to point a file owned by a different user, or (2) a symlink to the directory of a different user, which is used to determine privilege... Read more
Affected Products : suphp- Published: Apr. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-7812
The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker to downgrade the communication between the app and the server from TLS v1.2 to SSL v3.0, which may result in the attacker to eavesdrop... Read more
Affected Products : mitsubishi_ufj- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025