Latest CVE Feed
-
4.3
MEDIUMCVE-2023-4059
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog... Read more
Affected Products : profile_builder- Published: Sep. 04, 2023
- Modified: Mar. 06, 2025
-
4.3
MEDIUMCVE-2023-49754
Missing Authorization vulnerability in Yogesh Pawar, Clarion Technologies Bulk Edit Post Titles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Edit Post Titles: from n/a through 5.0.0.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2007-1390
Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.... Read more
Affected Products : dynaliens- Published: Mar. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1049
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the... Read more
- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3137
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid pa... Read more
Affected Products : wmscms- Published: Jun. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3593
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflo... Read more
Affected Products : manageengine_netflow_analyzer- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0643
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.... Read more
Affected Products : dev-c\+\+- Published: Jan. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3445
Buffer overflow in SJ Labs SJphone 1.60.303c, running under Windows Mobile 2003 on the Samsung SCH-i730 phone, allows remote attackers to cause a denial of service (device hang and call termination) via a malformed SIP INVITE message, a different vulnerab... Read more
- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-4246
The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_remote_install_handler function. This makes it possible for unaut... Read more
Affected Products : givewp- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48652
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.... Read more
- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5859
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.... Read more
Affected Products : coldfusion- Published: Feb. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-30537
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.... Read more
- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1262
Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character... Read more
Affected Products : squirrelmail- Published: May. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-44469
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770... Read more
Affected Products : lemonldap\- Published: Sep. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1103
Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of tr... Read more
- Published: Feb. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0817
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.... Read more
Affected Products : coldfusion- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1780
Cross-site scripting (XSS) vulnerability in the DHT shell (owdhtshell) in Overlay Weaver 0.5.9 to 0.5.11, when invoked with the -x option, allows remote attackers to inject arbitrary web script or HTML via fields in certain input forms.... Read more
Affected Products : overlay_weaver- Published: Mar. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-44689
e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to ... Read more
Affected Products : e-gov- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37968
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0814
Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin's ASP Chat allow remote attackers to inject arbitrary web script or HTML (1) via the psuedo (pseudo) field or (2) during chat.... Read more
Affected Products : adrenalins_asp_chat- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025