Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3388
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."... Read more
Affected Products : php- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-21620
A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change claims.... Read more
Affected Products : claim- Published: Feb. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-6037
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not ... Read more
Affected Products : mahara- Published: Nov. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6272
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1) help/sm/en/Output... Read more
Affected Products : openmanage_server_administrator- Published: Jan. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0010
Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," ... Read more
Affected Products : system_center_operations_manager- Published: Jan. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2836
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," w... Read more
Affected Products : phorum- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2769
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is n... Read more
Affected Products : sqwebmail- Published: Sep. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2734
Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : gallery- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-2481
The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.... Read more
Affected Products : libtiff- Published: Jul. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2736
Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : yapig- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-20229
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.... Read more
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0471
The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0792
Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a den... Read more
- Published: Apr. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-2480
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.... Read more
Affected Products : coldfusion_fusebox- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-4747
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20238
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping... Read more
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2406
Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.... Read more
Affected Products : opera_browser- Published: Aug. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-6465
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affect... Read more
Affected Products : email_security_appliance- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5554
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.... Read more
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20283
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.... Read more
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024