Latest CVE Feed
-
4.3
MEDIUMCVE-2007-5493
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.... Read more
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-39933
Insufficient verification vulnerability exists in Broadcast Mail CGI (pmc.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a user who can upload files through the product may execute an arbitrary exe... Read more
Affected Products :- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3265
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_application_server- Published: Jun. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3235
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection.... Read more
Affected Products : fuzzylime_forum- Published: Jun. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2068
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/... Read more
Affected Products : magmi- Published: Feb. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-2187
Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7 GT Rev.01 allows remote attackers to inject arbitrary web script or HTML via the level parameter in a redirect action, possibly involving interface/redirect.htm.php.... Read more
Affected Products : mjguest- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2000-1205
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_resp... Read more
Affected Products : http_server- Published: Feb. 01, 2000
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-6162
Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the pageAlias parameter. NOTE: The provenance of this information is unknown; the details are obtain... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Nov. 29, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-6162
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.... Read more
Affected Products : ability_mail_server- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-6108
Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : ec-cube- Published: Nov. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-1000503
MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view posts from private forums without having the password. This attack appear to be exploitable via Subscribe to a forum through IDOR. This v... Read more
Affected Products : mybb- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-0894
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.... Read more
Affected Products : nextcloud_server- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2005-4393
Cross-site scripting (XSS) vulnerability in show.cfm in e-publish CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) obcatid and (2) comid parameters.... Read more
Affected Products : e-publish- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4399
Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.... Read more
Affected Products : libertas_enterprise_cms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-1925
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possib... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2207
Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.... Read more
Affected Products : maian_gallery- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-1000114
The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the... Read more
Affected Products : datadog- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-2321
Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9176
Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php.... Read more
Affected Products : sexy_squeeze_pages- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2583
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.... Read more
Affected Products : mini_mail_dashboard_widget- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025