Latest CVE Feed
-
4.3
MEDIUMCVE-2008-1082
Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation.... Read more
Affected Products : opera_browser- Published: Feb. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2716
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ... Read more
Affected Products : real-time_location_system_controller activator b4_staff_badge_tag_firmware b4_staff_badge_tag- Published: Dec. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2285
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : liquibase_runner- Published: Sep. 23, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-1695
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame... Read more
Affected Products : safari- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-2311
A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration.... Read more
Affected Products : aws_global_configuration- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-9732
The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereferenc... Read more
- Published: Jun. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5178
Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1) creating a topic or (2) posting an answer. NOTE: some... Read more
Affected Products : easy_file_sharing_web_server- Published: Aug. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-0059
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described ... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 internet_explorer windows_vista windows_10_1607 windows_10_1507 +1 more products- Actively Exploited
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2020-2309
A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : kubernetes- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2689
Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php.... Read more
Affected Products : offria- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2642
HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : system_management_homepage- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2303
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified... Read more
Affected Products : active_directory- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2647
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : operations_agent- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5188
Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers to inject arbitrary web script or HTML via the EmailAddr parameter.... Read more
Affected Products : list_manager- Published: Aug. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-35559
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.... Read more
- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3479
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (applicatio... Read more
- Published: Jul. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3501
Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.... Read more
Affected Products : cordova- Published: Nov. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3489
lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords via a brute force attack.... Read more
Affected Products : cloudforms_3.0_management_engine- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3491
Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxe... Read more
Affected Products : foreman- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-4002
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party ... Read more
Affected Products : drupal- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025