Latest CVE Feed
-
4.3
MEDIUMCVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.... Read more
- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-47059
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Inva... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Feb. 27, 2025
-
4.3
MEDIUMCVE-2017-3315
Vulnerability in the PeopleSoft Enterprise HCM ePerformance component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network acces... Read more
Affected Products : peoplesoft_enterprise_human_capital_management_eperformance- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2012-4909
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-43032
autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.... Read more
Affected Products : autman- Published: Aug. 23, 2024
- Modified: Sep. 03, 2025
-
4.3
MEDIUMCVE-2009-4647
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit... Read more
Affected Products : secure_file_transfer_appliance- Published: Feb. 19, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4682
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.... Read more
Affected Products : good\/bad_vote- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-4331
Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary web script or HTML via the src parameter.... Read more
Affected Products : octavocms- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4684
Cross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the sign parameter.... Read more
Affected Products : ezodiak- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-6542
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.... Read more
- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-47845
Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.... Read more
Affected Products : grab_\&_save- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-0328
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Librar... Read more
Affected Products : wpcode- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
4.3
MEDIUMCVE-2008-1226
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions before 4.5.10 allow remote attackers to inject arbitrary web script or HTML via an e-mail attachment, possibly involving a (1... Read more
- Published: Mar. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-6351
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FBX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2295
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.... Read more
Affected Products : rgboard- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-12623
A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due ... Read more
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-0729
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a file-inclusion attack, aka Bug ID CSCuu11005.... Read more
Affected Products : secure_access_control_server- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3409
The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh3... Read more
- Published: Oct. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3487
Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified HTML header fields to (1) 400.php, (2) 403.ph... Read more
- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-44431
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT... Read more
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024