Latest CVE Feed
-
4.3
MEDIUMCVE-2011-5114
Multiple cross-site scripting (XSS) vulnerabilities in the Authoritative DNS - DNS Zones page in Barracuda Link Balancer 330 Firmware 1.3.2.005 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) zoneid or (2) scope param... Read more
- Published: Aug. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6328
Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to injec... Read more
Affected Products : websphere_portal- Published: Dec. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4780
Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter in a sitemap action, (2) the search parameter in a search action, (3) the ta... Read more
Affected Products : phpmyfaq- Published: Apr. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4745
Cross-site scripting (XSS) vulnerability in nav.html in PHPXref before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : phpxref- Published: Feb. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0847
Heap-based buffer overflow in the avfilter_filter_samples function in libavfilter/avfilter.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted media file.... Read more
Affected Products : ffmpeg- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-29627
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.... Read more
Affected Products : online_market_place_site- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6074
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14 allows remote attackers to inject arbitrary web script or HTML via an attached SVG file.... Read more
Affected Products : open-xchange_appsuite- Published: Nov. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-32170
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.... Read more
Affected Products : bytebase- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2025-27339
Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength allows Cross Site Request Forgery. This issue affects Minimum Password Strength: from n/a through 1.2.0.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2022-23994
An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.... Read more
Affected Products : wear_os- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-4320
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.... Read more
Affected Products : bitbucket- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2011-0004
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : matomo- Published: Jan. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5285
Multiple cross-site scripting (XSS) vulnerabilities in BugFree 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the ActionType parameter to Bug.php, the ReportMode parameter to (2) Report.php or (3) ReportLeft.php, or the PATH_I... Read more
Affected Products : bugfree- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-6035
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2-STABLE allows remote attackers to inject arbitrary web script or HTML via the atknodetype parameter.... Read more
Affected Products : achievo- Published: Feb. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5707
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604.... Read more
Affected Products : coursemill_learning_management_system- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3881
Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files.... Read more
Affected Products : zoneminder- Published: Sep. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-1569
Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web script via a javascript: URL in (1) a thread or (2) an IMG tag.... Read more
Affected Products : directtopics- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-11841
Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosur... Read more
Affected Products : arcsight_management_center- Published: Jun. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20485
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X... Read more
Affected Products : sterling_file_gateway- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-5257
webseald in WebSEAL 6.0.0.17 in IBM Tivoli Access Manager for e-business allows remote attackers to cause a denial of service (crash or hang) via HTTP requests, as demonstrated by a McAfee vulnerability scan.... Read more
Affected Products : tivoli_access_manager_for_e-business- Published: Nov. 27, 2008
- Modified: Apr. 09, 2025