Latest CVE Feed
-
4.3
MEDIUMCVE-2010-3926
Multiple cross-site scripting (XSS) vulnerabilities in Shop.cgi in SGX-SP Final before 11.00 and SGX-SP Final NE before 11.00 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 12, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4366
Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2) thread_description parameters in a message.... Read more
Affected Products : chameleon_social_networking- Published: Dec. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-40198
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.... Read more
Affected Products : terawallet- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2011
Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : deskpro- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-7776
Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.... Read more
Affected Products : garoon- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-8852
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0901
Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : flashy- Published: Mar. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2009
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath parameter to main/document/slideshow.php and the (2) file parameter to main/exe... Read more
Affected Products : dokeos- Published: Jun. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1938
Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).... Read more
- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4640
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Watch 1.0 allow remote attackers to inject arbitrary web script or HTML via the rev parameter to (1) bin/viewrev/Main/WebHome and (2) bin/view/Blog, and the (3) register_first_name and (4) regis... Read more
Affected Products : xwiki_watch- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1888
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in anoth... Read more
- Published: Feb. 29, 2024
- Modified: May. 12, 2025
-
4.3
MEDIUMCVE-2009-2448
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obta... Read more
Affected Products : online_guestbook_pro- Published: Jul. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-1475
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) ... Read more
Affected Products : my_little_forum- Published: Feb. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-0499
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrat... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware websphere_datapower_xc10_appliance websphere_datapower_service_gateway_xg45_virtual_edition_firmware websphere_datapower_service_gateway_xg45_virtual_edition websphere_datapower_service_gateway_xg45_firmware websphere_datapower_service_gateway_xg45 websphere_datapower_integration_appliance_xi52_virtual_edition_firmware websphere_datapower_integration_appliance_xi52_virtual_edition websphere_datapower_integration_appliance_xi52_firmware websphere_datapower_integration_appliance_xi52 +4 more products- Published: May. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-4928
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields.... Read more
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-31472
Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the data of Cabinet.... Read more
Affected Products : garoon- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31305
Cross-Site Request Forgery (CSRF) vulnerability in rtCamp Transcoder.This issue affects Transcoder: from n/a through 1.3.5. ... Read more
Affected Products :- Published: Apr. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-25770
libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.... Read more
Affected Products : libming- Published: Feb. 26, 2024
- Modified: Apr. 16, 2025
-
4.3
MEDIUMCVE-2009-4989
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action.... Read more
Affected Products : aj_auction_pro-oopd- Published: Aug. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4451
libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes th... Read more
Affected Products : wikkawiki- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025