Latest CVE Feed
-
4.3
MEDIUMCVE-2006-3197
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.... Read more
Affected Products : invision_power_board- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3155
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in (a) emailtofriend.pl or (b) violation.pl, (2) seller parameter in (c) vsoa.... Read more
Affected Products : ultimate_estate- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-12412
By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerabili... Read more
Affected Products : firefox- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4161
Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML via the domainname parameter to register.php, and other unspecified vectors. NOTE: the vendor has disput... Read more
Affected Products : milliscripts- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-13333
A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU... Read more
Affected Products : gitlab- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-3169
Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) msg_result and (2) rep_titre parameters in (a) read.php; and the (3) id and (4) parent parameters an... Read more
Affected Products : cs-forum- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4426
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action.... Read more
Affected Products : personal_information_manager- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3166
Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.... Read more
Affected Products : free_realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-10695
The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for au... Read more
Affected Products : futurio_extra- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
4.3
MEDIUMCVE-2005-2816
Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read... Read more
Affected Products : greymatter_forum- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-12404
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.... Read more
Affected Products : firefox- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2855
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : unclassified_newsboard- Published: Sep. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-5278
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).... Read more
Affected Products : wordpress- Published: Nov. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3089
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFactures 1.0, and possibly 1.2 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) prefixe_dossier parameter in (a) /inc/header.php; (2) msg parameter in (b) /r... Read more
Affected Products : phpmyfactures- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2783
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.... Read more
Affected Products : php_fusion- Published: Sep. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3095
Multiple cross-site scripting (XSS) vulnerabilities in iPostMX 2005 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the RETURNURL parameter in (1) userlogin.cfm and (2) account.cfm.... Read more
Affected Products : ipostmx_2005- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-8550
An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the ... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5181
Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : concrete5- Published: Dec. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2900
Cross-site scripting (XSS) vulnerability in top.php in CjLinkOut 1.0 allows remote attackers to inject arbitrary web script or HTML via the 123 parameter.... Read more
Affected Products : cjlinkout- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3026
Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp.... Read more
Affected Products : clickgallery- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025