Latest CVE Feed
-
4.3
MEDIUMCVE-2010-5302
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.... Read more
Affected Products : timthumb- Published: Aug. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3510
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote DTLS servers to cause a denial of service (NULL pointer dereference and client application crash) via a cra... Read more
Affected Products : openssl- Published: Aug. 13, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-1520
Cross-site scripting (XSS) vulnerability in logout.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.... Read more
Affected Products : taskfreak\!- Published: Jun. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4718
Multiple cross-site scripting (XSS) vulnerabilities in the Lyftenbloggie (com_lyftenbloggie) component 1.1.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) tag and (2) category parameters to index.php.... Read more
- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1218
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the f... Read more
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4772
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.... Read more
Affected Products : s-cms- Published: Mar. 23, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-34219
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API... Read more
Affected Products : teamcity- Published: May. 31, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1707
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.... Read more
Affected Products : piwigo- Published: May. 04, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12244
An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prio... Read more
Affected Products : gitlab- Published: Apr. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2010-2455
Opera does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.... Read more
Affected Products : opera_browser- Published: Jun. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4766
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstanc... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2531
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the applic... Read more
- Published: Aug. 20, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1594
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some ... Read more
Affected Products : ocs_inventory_ng- Published: Apr. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0468
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : commonspot_content_server- Published: Feb. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13118
The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack... Read more
Affected Products : ip_based_login- Published: Mar. 25, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2010-1614
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is... Read more
Affected Products : moodle- Published: Apr. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2846
Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the afmsg parameter to index.php.... Read more
- Published: Jul. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4757
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obt... Read more
Affected Products : e107- Published: Mar. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4748
Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : pmwiki- Published: Mar. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4521
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report p... Read more
Affected Products : birt- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025