Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10971
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.... Read more
Affected Products : devolutions_server- Published: Nov. 12, 2024
- Modified: Jun. 27, 2025
-
4.3
MEDIUMCVE-2009-5099
Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI Server 1.7.0.1062 and earlier allows remote attackers to inject arbitrary web script or HTML via the outputType parameter.... Read more
Affected Products : bi_server- Published: Sep. 13, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4250
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to register.php; (2) the user parameter to search.php; th... Read more
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-0197
Cross-site scripting (XSS) vulnerability in the filter_draw_selection_area2 function in core/filter_api.php in MantisBT 1.2.12 before 1.2.13 allows remote attackers to inject arbitrary web script or HTML via the match_type parameter to bugs/search.php.... Read more
Affected Products : mantisbt- Published: May. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4252
Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: some of these details are obtained from third party informati... Read more
Affected Products : image_hosting_script_dpi- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3262
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) v... Read more
- Published: May. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1864
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML doc... Read more
- Published: May. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-1002
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to inject arbitrary web script or HTML via a crafted javascript: URL.... Read more
Affected Products : safari- Published: Mar. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3007
Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ.... Read more
Affected Products : shoutcast_server- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2324
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype or searchterm parameters to (1) results.php or (2) categorysearch.php.... Read more
Affected Products : clever_copy- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3000
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : okarticles- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-10852
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authe... Read more
Affected Products : buy_one_click_woocommerce- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
4.3
MEDIUMCVE-2009-5092
Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 12, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4171
An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long a... Read more
Affected Products : messenger- Published: Dec. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3914
Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation.... Read more
- Published: Nov. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4185
Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.... Read more
Affected Products : system_management_homepage- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3858
Cross-site scripting (XSS) vulnerability in GejoSoft allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI in photos/tags.... Read more
Affected Products : gejosoft- Published: Nov. 04, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4062
Multiple cross-site scripting (XSS) vulnerabilities in the Printfriendly module 6.x before 6.x-1.6 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2992
Cross-site scripting (XSS) vulnerability in display.asp in My Photo Scrapbook 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the key_m parameter.... Read more
Affected Products : my_photo_scrapbook- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-1225
Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024