Latest CVE Feed
-
4.3
MEDIUMCVE-2017-10132
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/iOS). The supported version that is affected is 1.05. Easily exploitable vulnerability allows low privileged attacker with network access via ... Read more
Affected Products : hospitality_hotel_mobile- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2008-4888
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : netrisk- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4959
Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained... Read more
- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5119
Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.... Read more
Affected Products : dxshopcart- Published: Nov. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1828
The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices allows remote attackers to cause a denial of service (disk consumption) by uploading a large file.... Read more
Affected Products : ithoughtshd- Published: Mar. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2925
Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to a... Read more
- Published: Apr. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-6565
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.... Read more
Affected Products : invision_power_board- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2416
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.... Read more
Affected Products : contrexx- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-4998
Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : starcms- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-6978
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.... Read more
- Published: Feb. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2926
Cross-site scripting (XSS) vulnerability in Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header to index.php.... Read more
Affected Products : phptraffica- Published: Apr. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3506
Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.... Read more
Affected Products : cmsphp- Published: Oct. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4047
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote attackers to inject arbitrary web script or HTML via a crafted link.... Read more
Affected Products : spss_analytical_decision_management- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-33573
Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1. ... Read more
Affected Products :- Published: May. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10743
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP'... Read more
- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-7080
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.... Read more
Affected Products : content_management_system- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-2408
Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : palm_webos- Published: Aug. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2485
Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : logicampus- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-0851
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category param... Read more
- Published: Feb. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-7158
Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter. NOTE: it is likely that this issue overlaps... Read more
Affected Products : apex- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025