Latest CVE Feed
-
4.3
MEDIUMCVE-2023-2286
The WP Activity Log for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the ajax_run_cleanup function. This makes it possible for unauthenticated attack... Read more
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-27592
Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.... Read more
Affected Products : corezoid- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2020-8877
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
- Published: Mar. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-0822
Cross-site scripting (XSS) vulnerability in Joomla! 1.6 and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0820.... Read more
Affected Products : joomla\!- Published: Sep. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2999
The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsExcept... Read more
Affected Products : android- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-31942
Cross-Site Request Forgery (CSRF) vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through 3.0.2. ... Read more
Affected Products : calendarista- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5145
Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attacke... Read more
Affected Products : windows_xp- Published: Oct. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-7314
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.... Read more
Affected Products : gollum- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5916
Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the WP e-Commerce plugin, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.... Read more
Affected Products : bradesco_gateway- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20630
Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2985
Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : bbs_x102- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5992
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script ... Read more
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4190
Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683.... Read more
Affected Products : prime_service_catalog- Published: Jun. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-1905
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened... Read more
Affected Products : whatsapp- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5314
Cross-site scripting (XSS) vulnerability in ViewGit 0.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the f parameter.... Read more
Affected Products : viewgit- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-2991
Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : evenzia_cms- Published: Jun. 04, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1620
Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters.... Read more
Affected Products : matachat- Published: May. 12, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1712
Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters. NOTE: some of these details are obtained... Read more
Affected Products : wbnews- Published: May. 04, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-26031
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).... Read more
Affected Products : zammad- Published: Dec. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4290
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.... Read more
Affected Products : moodle- Published: Jul. 16, 2012
- Modified: Apr. 11, 2025