Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2845
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.... Read more
- Published: Oct. 25, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4329
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or... Read more
Affected Products : phpmyadmin- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1804
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions ... Read more
- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1789
splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYu... Read more
Affected Products : poppler- Published: Apr. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1808
Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script ... Read more
Affected Products : zeroclipboard- Published: Apr. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1812
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.... Read more
- Published: Dec. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1490
Unspecified vulnerability in Oracle Java SE 7 Update 11 (JRE 1.7.0_11-b21) allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors, aka "Issue 51," a different vulnerability than CVE-2013-0431. NOTE: as of 201301... Read more
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1501
Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Login.... Read more
Affected Products : e-business_suite- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1896
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling... Read more
- Published: Jul. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1879
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."... Read more
Affected Products : activemq- Published: Jul. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4995
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some ... Read more
Affected Products : limesurvey- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1471
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Ad... Read more
Affected Products : fortimail fortimail-2000b fortimail-200d fortimail-400c fortimail-5002b fortimail-vm2000- Published: Feb. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-4293
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.... Read more
Affected Products : clickcartpro- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2999
Cross-site scripting (XSS) vulnerability in search.php in OkScripts QuickLinks 1.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : quicklinks- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4668
Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via the task_id parameter in an edit_task command.... Read more
Affected Products : ackertodo- Published: Sep. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2965
Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."... Read more
Affected Products : particle_whois- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2984
Cross-site scripting (XSS) vulnerability in index.php in IntegraMOD 1.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the STYLE_URL parameter. NOTE: it is possible that this issue is resultant from SQL injection.... Read more
Affected Products : integramod- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3017
PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS).... Read more
Affected Products : content2web- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-13313
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.... Read more
Affected Products : gitlab- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-13354
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=... Read more
Affected Products : gitlab- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024