Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2545
Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML ... Read more
Affected Products : spa_501g_8-line_ip_phone spa_502g_1-line_ip_phone spa_504g_4-line_ip_phone spa_508g_8-line_ip_phone spa_509g_12-line_ip_phone spa_512g_1-line_ip_phone spa_514g_4-line_ip_phone spa_525g_5-line_ip_phone spa_525g2_5-line_ip_phone spa8000_8-port_ip_telephony_gateway_firmware +8 more products- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3835
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to for... Read more
Affected Products : open_source_security_information_management- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-32075
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can... Read more
Affected Products : customer_management_framework- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1716
The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_form() function in all versions up to, and including, 1.0.2.2. This makes it possible for authenticated attackers... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6601
Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2)... Read more
- Published: Dec. 15, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1482
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.... Read more
Affected Products : cms_made_simple- Published: May. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3438
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect ... Read more
Affected Products : graphicsmagick- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6903
Sophos Anti-Virus for Windows before 7.6.3, Anti-Virus for Windows NT/9x before 4.7.18, Anti-Virus for OS X before 4.9.18, Anti-Virus for Linux before 6.4.5, Anti-Virus for UNIX before 7.0.5, Anti-Virus for Unix and Netware before 4.37.0, Sophos EM Librar... Read more
- Published: Aug. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-1288
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it possi... Read more
Affected Products : schema_\&_structured_data_for_wp_\&_amp- Published: Feb. 29, 2024
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2013-2309
Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version col... Read more
Affected Products : openpne- Published: Jun. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-4103
The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() f... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3500
Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.... Read more
Affected Products : suggested_terms_module- Published: Aug. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4898
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.... Read more
Affected Products : rateme- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-40344
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : delphix- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3730
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly... Read more
Affected Products : revize_cms- Published: Nov. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-37073
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the detection result is tampered with.... Read more
Affected Products : harmonyos- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1114
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527.... Read more
Affected Products : unity_express_software- Published: Feb. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1176
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 0.9.9.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) Gallery Comments pages, (2) Feedback pages, (3) Search Results pages, and (4)... Read more
Affected Products : webapp- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-22229
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs th... Read more
Affected Products : unity_operating_environment unity_xt_operating_environment unityvsa_operating_environment- Published: Jan. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-21252
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.... Read more
Affected Products : mattermost_server- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024