Latest CVE Feed
-
4.3
MEDIUMCVE-2004-2749
Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported a... Read more
Affected Products : homeportal- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0462
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.... Read more
Affected Products : mercuryboard- Published: Feb. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1341
Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.... Read more
Affected Products : info2www- Published: Apr. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-44186
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASL... Read more
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-34056
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.... Read more
Affected Products : vcenter_server- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2752
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.... Read more
Affected Products : postnuke- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2766
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than... Read more
- Published: Jan. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-1397
Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl.... Read more
Affected Products : usemodwiki- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-32344
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898.... Read more
- Published: Feb. 26, 2024
- Modified: Dec. 17, 2024
-
4.3
MEDIUMCVE-2023-46652
A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins.... Read more
Affected Products : lambdatest-automation- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2435
Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.... Read more
Affected Products : website_baker- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-2546
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: SQL Extensions). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vu... Read more
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-20862
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary... Read more
Affected Products : unified_communications_manager- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-2557
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005... Read more
- Published: Sep. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-32599
Missing Authorization vulnerability in Bill Minozzi reCAPTCHA for all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects reCAPTCHA for all: from n/a through 1.22.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2005-1494
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.... Read more
Affected Products : megabook- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1320
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : mnemo- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2476
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : shopping_cart- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-34047
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOpti... Read more
Affected Products : spring_for_graphql- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-1359
Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : text.cgi- Published: May. 02, 2005
- Modified: Apr. 03, 2025