Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1569
Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web script via a javascript: URL in (1) a thread or (2) an IMG tag.... Read more
Affected Products : directtopics- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-7417
Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery... Read more
Affected Products : ipcop- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5706
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater t... Read more
Affected Products : coursemill_learning_management_system- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-0231
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.... Read more
Affected Products : financial_transaction_manager- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-0726
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.... Read more
Affected Products : dragonfly_cms- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-15577
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.... Read more
Affected Products : gitlab- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-10035
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEcho parameter to comments_paginate.php or (2) stores_paginate.php or the (3) a... Read more
Affected Products : couponphp- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-0650
Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a res... Read more
Affected Products : cpaint- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-100030
Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a ByEge action.... Read more
Affected Products : ganesha_digital_library- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-0432
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : phpautovideo- Published: Jan. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-42126
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries ... Read more
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-39226
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a malicious actor can add large payloads of text into the Location and Website fields o... Read more
Affected Products : discourse- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-38974
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.... Read more
Affected Products : wpml- Published: Nov. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-1196
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.... Read more
Affected Products : garoon- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-4580
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-38788
An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK ... Read more
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-7020
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
Affected Products : chrome- Published: Sep. 23, 2024
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2005-3156
Directory traversal vulnerability in printfaq.php in EasyGuppy (Guppy for Windows) 4.5.4 and 4.5.5 allows remote attackers to read arbitrary files via ".." sequences in the pg parameter, which is cleansed for XSS but not directory traversal.... Read more
Affected Products : easyguppy- Published: Oct. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-4565
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm p... Read more
Affected Products : verification_code_for_comments- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-38756
A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening... Read more
Affected Products : groupwise- Published: Dec. 16, 2022
- Modified: Apr. 18, 2025