Latest CVE Feed
-
4.3
MEDIUMCVE-2018-0929
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how Interne... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-1657
Cross-site scripting (XSS) vulnerability in index.php in Chucky A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not filtered when the administrator views the "Login Log" page.... Read more
Affected Products : n.t.- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3795
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary web script or HTML via (1) the Err parameter in admin/index.php and the (2) firstname and (3) lastname parameters in ind... Read more
Affected Products : affiliate_network_pro- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-20227
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk ro... Read more
- Published: Mar. 26, 2025
- Modified: Jul. 21, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2005-3771
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) "GET and other variables" and (2) "SEF".... Read more
Affected Products : joomla- Published: Nov. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-16426
Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.... Read more
- Published: Sep. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3688
Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page.... Read more
Affected Products : xmb- Published: Nov. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4206
Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID para... Read more
Affected Products : aspplayground.net- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3285
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.... Read more
Affected Products : comersus_backoffice_plus- Published: Oct. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-4730
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.... Read more
Affected Products : xorg-server- Published: Sep. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-1094
Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.... Read more
Affected Products : zenworks_configuration_management- Published: Jun. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1903
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.... Read more
- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1731
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called wit... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1682
Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script.... Read more
Affected Products : web\+_shop- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-47593
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2006-0796
Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information i... Read more
Affected Products : clever_copy- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-6177
Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jun. 27, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0780
Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.... Read more
Affected Products : perlblog- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0050
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.... Read more
Affected Products : lasso- Published: Jan. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1724
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors relate... Read more
- Published: Jul. 09, 2009
- Modified: Apr. 09, 2025