Latest CVE Feed
-
4.3
MEDIUMCVE-2012-1050
Directory traversal vulnerability in Mathopd 1.4.x and 1.5.x before 1.5p7, when configured with the * construct for mass virtual hosting, allows remote attackers to read arbitrary files via a crafted Host header.... Read more
Affected Products : mathopd- Published: Feb. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5225
Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5233
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.... Read more
Affected Products : irfanview- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5255
Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or (3) password parameter.... Read more
Affected Products : x3_cms- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5263
Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the server parameter.... Read more
Affected Products : netweaver- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5253
Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header.... Read more
Affected Products : dl- Published: Jan. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5267
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict ... Read more
Affected Products : wikiwig- Published: Nov. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5304
Multiple cross-site scripting (XSS) vulnerabilities in the Sodahead Polls plugin before 2.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) the poll_id parameter to customizer.php or (2) the customize parameter to pol... Read more
Affected Products : sodahead_polls- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-5258
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontr... Read more
Affected Products : orangehrm- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5264
Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xml_or_all parameter.... Read more
- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0233
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.... Read more
Affected Products : advantech_webaccess- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-20319
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affected dev... Read more
Affected Products : ios_xr- Published: Mar. 13, 2024
- Modified: Jul. 07, 2025
-
4.3
MEDIUMCVE-2011-0009
Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.... Read more
- Published: Jan. 25, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-17489
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in ... Read more
- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1005
Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog... Read more
Affected Products : mobile_web_server- Published: Feb. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-7138
Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.... Read more
Affected Products : google_calendar_events- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0285
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : webnetwork- Published: Jan. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0322
The EStrongs ES File Explorer application 1.6.0.2 through 1.6.1.1 for Android does not properly restrict access, which allows remote attackers to read arbitrary files via vectors involving an unspecified function.... Read more
- Published: Mar. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2743
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the action parameter to (1) the default URI or (2) includes/javascript.php, or the (3) title or (4) body paramet... Read more
Affected Products : chyrp- Published: Jul. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0296
Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_gateway- Published: May. 21, 2012
- Modified: Apr. 11, 2025