Latest CVE Feed
-
4.3
MEDIUMCVE-2024-5005
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose proje... Read more
Affected Products : gitlab- Published: Oct. 11, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2006-4310
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI.... Read more
Affected Products : firefox- Published: Aug. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-6085
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) vedipm or (2) live_chat module.... Read more
Affected Products : vigilecms- Published: Nov. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5980
Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).... Read more
Affected Products : eggblog- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6677
Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.... Read more
Affected Products : random_anti-spam_image- Published: Jan. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6673
Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action.... Read more
Affected Products : makale_scripti- Published: Jan. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6001
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vu... Read more
Affected Products : bandersnatch- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0416
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a... Read more
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-3740
Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)... Read more
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6669
Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter.... Read more
Affected Products : phcdownload- Published: Jan. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-3856
Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-53112
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific ... Read more
Affected Products : glpi- Published: Jul. 30, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-25250
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full S... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2008-0988
Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.... Read more
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0462
Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1345
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and earlier allows remote attackers to inject arbitrary web script or HTML via the day parameter in a dayview action.... Read more
Affected Products : easycalendar- Published: Mar. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-12140
The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render function due to insufficient restrictions on which temp... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2008-0757
Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private m... Read more
Affected Products : mercuryboard_message_board- Published: Feb. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-12327
The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in all versions up to, and including, 1.0.7. This makes it possible for authent... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-12719
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authe... Read more
Affected Products : wordpress_file_upload- Published: Jan. 07, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Path Traversal