Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1116
Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.... Read more
Affected Products : phpbb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-30518
A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : thycotic_secret_server- Published: Apr. 12, 2023
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2006-4821
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal_userreview_module- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2476
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : shopping_cart- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3237
Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML via the t_login parameter of footer.php.... Read more
Affected Products : cyphor- Published: Oct. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-29178
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd proc... Read more
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2814
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.... Read more
Affected Products : flatnuke- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1068
Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.... Read more
Affected Products : scssboard- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-36074
Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue re... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2574
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.... Read more
Affected Products : phpgroupware- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-28406
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not contro... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +9 more products- Published: May. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1713
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.... Read more
Affected Products : serendipity- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-28284
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability... Read more
Affected Products : edge- Published: Apr. 11, 2023
- Modified: Feb. 28, 2025
-
4.3
MEDIUMCVE-2021-36001
Adobe Character Animator version 4.2 (and earlier) is affected by an out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the cont... Read more
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47593
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2005-1316
Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : accounts- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1146
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different v... Read more
Affected Products : calendarscript- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUM- Published: Nov. 03, 2023
- Modified: Jan. 01, 2025
-
4.3
MEDIUMCVE-2021-35991
Adobe Bridge version 11.0.2 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the... Read more
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1727
A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to ... Read more
Affected Products : gradio- Published: Mar. 21, 2024
- Modified: Jul. 30, 2025