Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2939
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web scr... Read more
- Published: Aug. 06, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-3981
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.... Read more
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0588
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_li... Read more
Affected Products : paid_memberships_pro- Published: Apr. 09, 2024
- Modified: Jan. 17, 2025
-
4.3
MEDIUMCVE-2008-2938
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in ... Read more
Affected Products : tomcat- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2973
Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters.... Read more
Affected Products : mm_chat- Published: Jul. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2975
Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.... Read more
Affected Products : tinx_cms- Published: Jul. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0706
Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.... Read more
Affected Products : gastebuch- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0699
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : qwikiwiki- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-4288
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160631.... Read more
Affected Products : maximo_anywhere- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUM- Published: May. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2911
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.... Read more
Affected Products : contendio- Published: Jun. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2855
Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : ownrs- Published: Jun. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-4056
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.... Read more
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2861
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail ... Read more
Affected Products : site_composer- Published: Jun. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-4257
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.... Read more
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3451
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.... Read more
Affected Products : cxf- Published: Sep. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-2814
Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; t... Read more
Affected Products : wallcity-server_shoutcast_admin_panel- Published: Jun. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2795
Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.... Read more
Affected Products : ultraedit- Published: Jun. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-24695
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, un... Read more
Affected Products : bluetooth_core_specification- Published: Jun. 02, 2023
- Modified: Jan. 10, 2025
-
4.3
MEDIUMCVE-2008-3773
Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka new... Read more
Affected Products : vbulletin- Published: Aug. 22, 2008
- Modified: Apr. 09, 2025