Latest CVE Feed
-
4.3
MEDIUMCVE-2024-9929
A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2009-2897
Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Applica... Read more
- Published: Oct. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3736
Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file.... Read more
- Published: May. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3846
Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mysql-lists- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-13710
The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on the 'estatebud_settings' page. This makes it possib... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-47642
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As ... Read more
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2221
Cross-site scripting (XSS) vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : php-i-board- Published: Jun. 26, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-22695
Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support. This issue affects Nirweb support: from n/a through 3.0.3.... Read more
Affected Products : nirweb_support- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2022-25783
Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.... Read more
- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-5043
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.... Read more
Affected Products : free_mp3_player- Published: Dec. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3367
Cross-site scripting (XSS) vulnerability in the vCloud Director component in Cisco Nexus 1000V InterCloud for VMware allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq90524.... Read more
Affected Products : cisco_nexus_1000v_intercloud- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-0796
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce valida... Read more
Affected Products : woot- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2932
Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.... Read more
Affected Products : netweaver- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-0655
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- Published: Feb. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-4386
The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack... Read more
Affected Products : intuitive_custom_post_order- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
4.3
MEDIUMCVE-2014-8314
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA Developer Edition Revision 70 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) epm/admin/DataGen.xsjs or (2) epm/services/multiply.xsjs in the demo... Read more
Affected Products : hana- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1052
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web script or HTML via the result parameter to upload_files/pk/include.php.... Read more
Affected Products : phpkit- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-8811
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.... Read more
Affected Products : bludit- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-35972
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.... Read more
Affected Products : yzmcms- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8006
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.... Read more
Affected Products : isb8320-e_high-definition_ip-only_dvr- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025