Latest CVE Feed
-
4.3
MEDIUMCVE-2010-3291
Cross-site scripting (XSS) vulnerability in HP AssetCenter 5.0x through AC_5.03, and AssetManager 5.1x through AM_5.12 and 5.2x through AM_5.22, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-27907
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.... Read more
Affected Products : nexus_repository_manager- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-3429
Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies v... Read more
Affected Products : mailsite_express- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-36759
The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated... Read more
Affected Products : woody_code_snippets- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5490
Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : plone- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8751
Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress 13.00.06 allow remote attackers to inject arbitrary web script or HTML via the (1) search_param parameter to search.php or (2) name, (3) address, or (4) comment parameter to forms.php.... Read more
Affected Products : webpress- Published: Dec. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2002
Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : c-board_moyuku- Published: Jun. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1449
The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMajor field. NOTE: this may later be SPLIT into multiple CVEs if additional information is pu... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-3560
Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : kshop_module- Published: Aug. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3506
Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.... Read more
Affected Products : cmsphp- Published: Oct. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4802
Cross-site scripting (XSS) vulnerability in HP Application Lifecycle Management (ALM) Quality Center before 11.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka ZDI-CAN-1565.... Read more
Affected Products : application_lifecycle_management- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7018
Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an ad... Read more
Affected Products : easy_php_calendar- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-45250
ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
4.3
MEDIUMCVE-2014-1888
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited with... Read more
- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-3514
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.... Read more
Affected Products : chipmunk_forum- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2924
Cross-site scripting (XSS) vulnerability in Webmatic before 2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4888
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : netrisk- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-8345
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no i... Read more
Affected Products : es_file_explorer_file_manager- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1332
Cross-site scripting (XSS) vulnerability in PrettyBook PrettyFormMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : prettyformmail- Published: Apr. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-1205
Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when... Read more
Affected Products : mybloggie- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025