Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2976
Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving a BUGLIST cookie.... Read more
Affected Products : bugzilla- Published: Aug. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2438
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.... Read more
Affected Products : usebb- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5649
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.... Read more
Affected Products : socketmail- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5061
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible for developers to... Read more
Affected Products : gitlab- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5339
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-5478
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3040
Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.... Read more
- Published: Mar. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0258
Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : phprunman- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-0159
A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability."... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2018-1025
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge.... Read more
- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0998
An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0892.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1627
The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : my_private_site- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-6300
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.... Read more
Affected Products : cutenews- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5652
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an I... Read more
Affected Products : iplanet_messaging_server_messenger_express- Published: Nov. 03, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-0927
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Serv... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5626
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the ... Read more
Affected Products : phpfaber_content_management_system- Published: Oct. 31, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5598
Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.... Read more
Affected Products : goop_gallery- Published: Oct. 28, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-0643
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.... Read more
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5564
Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third par... Read more
Affected Products : md-pro- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5560
Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE:... Read more
Affected Products : progsys- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025