Latest CVE Feed
-
4.3
MEDIUMCVE-2013-6738
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authori... Read more
Affected Products : smartcloud_analytics_log_analysis- Published: Apr. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3793
CFPreferences in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.... Read more
Affected Products : iphone_os- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6674
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message contain... Read more
- Published: Feb. 17, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6780
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.... Read more
Affected Products : yui- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0236
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.... Read more
Affected Products : wordpress- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-2484
Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.... Read more
Affected Products : web_mail- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-3408
The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers ... Read more
Affected Products : bricks- Published: Aug. 17, 2024
- Modified: Sep. 13, 2024
-
4.3
MEDIUMCVE-2018-8112
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.... Read more
Affected Products : edge- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-6581
Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to bypass intended restrictions on reading keys in the product's keyring, and trigger outbound e-mail messages signed by an arbitrary st... Read more
Affected Products : request_tracker- Published: Jul. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-41975
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A website may be able to access the microphone without the microphone use indicator being shown.... Read more
Affected Products : macos- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3207
Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/undefined1.... Read more
Affected Products : sks_keyserver- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3480
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (applicatio... Read more
- Published: Jul. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-8324
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2... Read more
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3494
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.... Read more
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-41977
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, iOS 16.7.2 and iPadOS 16.7.2. Visiting a malicious website may reveal browsing history.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-8388
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383.... Read more
Affected Products : edge- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5881
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.... Read more
Affected Products : yui- Published: Nov. 16, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3678
Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : monitoring_plugin- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3924
Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.... Read more
- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-5534
Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: so... Read more
Affected Products : online_shop- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025