Latest CVE Feed
-
4.3
MEDIUMCVE-2015-6529
Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter to site/error.php or (2) ip parameter to site/tools/searchResults.php.... Read more
Affected Products : phpipam- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-14722
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete an e-mail forwarding destination from a victim's account via an attacker account.... Read more
Affected Products : webpanel- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10743
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP'... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2085
Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rf... Read more
Affected Products : phpcodecabinet- Published: Feb. 04, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-39347
The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users... Read more
Affected Products : stripe_for_woocommerce- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-0503
The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack... Read more
Affected Products : free_woocommerce_theme_99fy_extension- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
4.3
MEDIUMCVE-2010-1105
Cross-site scripting (XSS) vulnerability in cgi/index.php in AdvertisementManager 3.1.0 and 3.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter.... Read more
Affected Products : advertisementmanager- Published: Mar. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2825
The DNP3 service in the Outstation component on Elecsys Director Gateway devices with kernel 2.6.32.11ael1 and earlier allows remote attackers to cause a denial of service (CPU consumption and communication outage) via crafted input.... Read more
- Published: Dec. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6592
Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to... Read more
Affected Products : safari- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-7777
Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.... Read more
Affected Products : void- Published: Nov. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-2310
Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.... Read more
- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-5391
Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).... Read more
Affected Products : jobscheduler- Published: Sep. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2004-1630
Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.... Read more
Affected Products : work_flow_engine- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-1548
IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.... Read more
Affected Products : api_connect- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4433
Cross-site scripting (XSS) vulnerability in textfilesearch.aspx in the Text File Search ASP.NET edition allows remote attackers to inject arbitrary web script or HTML via the search field.... Read more
Affected Products : text_file_search- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3342
Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.... Read more
Affected Products : easypublish- Published: Jul. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-0911
inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.... Read more
Affected Products : websphere_mq- Published: May. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-1983
Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-1317
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.... Read more
- Published: Feb. 09, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1908
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : splunk- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025