Latest CVE Feed
-
4.3
MEDIUMCVE-2010-3712
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.p... Read more
Affected Products : joomla\!- Published: Oct. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4451
libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes th... Read more
Affected Products : wikkawiki- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-10104
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a ... Read more
Affected Products : zammad- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30526
Cross-Site Request Forgery (CSRF) vulnerability in Easy Social Feed.This issue affects Easy Social Feed: from n/a through 6.5.6. ... Read more
Affected Products : easy_social_feed- Published: Mar. 31, 2024
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2007-3712
Multiple cross-site scripting (XSS) vulnerabilities in HiddenChest "is ve Bayi Basvuru Formu" (Yb ve Bayi Babvuru Formu) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is un... Read more
Affected Products : yb_ve_bayi_babvuru_formu- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-2947
Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network acc... Read more
Affected Products : peoplesoft_enterprise_human_capital_management_absence_management- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4823
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.... Read more
Affected Products : cpanel- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-10979
GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.... Read more
Affected Products : gitlab- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1287
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally f... Read more
Affected Products : php- Published: Mar. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-40344
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : delphix- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3529
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message par... Read more
- Published: May. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-16388
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was disco... Read more
Affected Products : pega_platform- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4931
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible ... Read more
Affected Products : backupwordpress- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-2470
Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_message parameter.... Read more
Affected Products : really_simple_chat- Published: Jun. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-0857
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.... Read more
- Published: Feb. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3363
Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the "plain textarea editor."... Read more
- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1482
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.... Read more
Affected Products : cms_made_simple- Published: May. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-16752
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user priv... Read more
Affected Products : dash_core decentralized_anonymous_payment_system private_instant_verified_transactions- Published: Dec. 04, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1910
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenti... Read more
- Published: Jun. 09, 2023
- Modified: Nov. 25, 2024
-
4.3
MEDIUMCVE-2004-2171
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.... Read more
Affected Products : cherokee_httpd- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025