Latest CVE Feed
-
4.3
MEDIUMCVE-2014-5136
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : sierra- Published: Sep. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-3317
Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.... Read more
- Published: May. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-42069
When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5110
Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HTML via the id_nodo parameter.... Read more
- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-38313
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.... Read more
Affected Products : firefox- Published: Jun. 13, 2024
- Modified: Mar. 14, 2025
-
4.3
MEDIUMCVE-2021-37532
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.... Read more
Affected Products : business_one- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3947
The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to missing or incorrect nonce validation on the wptodo_settings() function. This makes it possible for unauthenticated a... Read more
Affected Products : wp_to_do- Published: May. 30, 2024
- Modified: Feb. 12, 2025
-
4.3
MEDIUMCVE-2022-0444
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new bac... Read more
Affected Products : xcloner- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6819
Cross-site scripting (XSS) vulnerability in Performance Provider in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : netweaver- Published: Nov. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6816
Multiple cross-site scripting (XSS) vulnerabilities in the (1) JavaDumpService and (2) DataCollector servlets in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : netweaver- Published: Nov. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6135
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-25601
On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use ver... Read more
Affected Products : dolphinscheduler- Published: Apr. 20, 2023
- Modified: Feb. 13, 2025
-
4.3
MEDIUMCVE-2022-36953
In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.... Read more
Affected Products : netbackup- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20580
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.... Read more
Affected Products : planning_analytics- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36968
In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.... Read more
Affected Products : ipswitch_ws_ftp_server- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-7370
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Bolt Browser vers... Read more
Affected Products : bolt_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4549
Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes par... Read more
Affected Products : woocommerce_sagepay_direct_payment_gateway- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-3962
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error r... Read more
- Published: Sep. 23, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22108
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is... Read more
- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-5900
Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16. ... Read more
Affected Products : pkp_web_application_library- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024