Latest CVE Feed
-
4.3
MEDIUMCVE-2014-3265
Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900.... Read more
Affected Products : security_manager- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0532
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler be... Read more
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2124
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.... Read more
Affected Products : dynamic_extended_choice_parameter- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2724
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low pr... Read more
Affected Products : flexcube_investor_servicing- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-100026
Cross-site scripting (XSS) vulnerability in readme.php in the April's Super Functions Pack plugin before 1.4.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained f... Read more
Affected Products : april\'s_super_functions_pack- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3166
The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sen... Read more
- Published: Aug. 13, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-29130
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.... Read more
- Published: Nov. 26, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-10028
Cross-site scripting (XSS) vulnerability in D-Link DAP-1360 router with firmware 2.5.4 and later allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi when res_config_id is set to 41.... Read more
- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2117
A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capt... Read more
Affected Products : pipeline_github_notify_step- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-29451
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version... Read more
- Published: Feb. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0265
Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pkt... Read more
- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-10009
Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to th... Read more
Affected Products : stark_crm- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-27774
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to ... Read more
- Published: Dec. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3149
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before 20140424, allows remote attackers to inject ar... Read more
- Published: Jul. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2589
Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.... Read more
Affected Products : nsa_2400- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2536
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file c... Read more
- Published: Mar. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-5076
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Ce... Read more
- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-100038
Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter to search/.... Read more
Affected Products : storytlr- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-5587
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.... Read more
Affected Products : phppgadmin- Published: Dec. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-2757
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthen... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight oncommand_workflow_automation jdk jre +11 more products- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024