Latest CVE Feed
-
4.3
MEDIUMCVE-2013-6919
The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.... Read more
Affected Products : phpthumb- Published: Dec. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0940
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-TSAM-LA0041 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) REST API or (2) Self Service UI... Read more
Affected Products : tivoli_service_automation_manager- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6974
Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud89431.... Read more
Affected Products : secure_access_control_system- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0922
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.... Read more
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0335
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Serena Dimensions CM 12.2 build 7.199.0 allow remote attackers to inject arbitrary web script or HTML via the (1) DB_CONN, (2) DB_NAME, (3) DM_HOST, (4) MAN_DB_NAME, (5) framecmd, (6... Read more
Affected Products : dimensions_cm- Published: Mar. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0584
Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
Affected Products : coldfusion- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0955
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0 before 8.0.0.1 CF12, when Social Rendering in Connections integration is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_portal- Published: May. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0921
The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.... Read more
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6960
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meeting Center allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36248.... Read more
Affected Products : webex_meeting_center- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0871
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially sensitive Tomcat stack-trace information via non-printing characters in a cookie to the /classes/ URI, as ... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-27958
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.... Read more
Affected Products : ohio_supercomputer_center_open_ondemand- Published: Feb. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-7001
The Multimedia Messaging Centre (MMSC) in NowSMS Now SMS & MMS Gateway before 2013.11.15 allows remote attackers to cause a denial of service via a malformed MM1 message that is routed to a (1) MM4 or (2) MM7 connection.... Read more
Affected Products : now_sms_\&_mms_gateway- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2138
CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCun82349.... Read more
Affected Products : security_manager- Published: Apr. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1263
curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fie... Read more
- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-1917
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2014-0620
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web script or HTML via the (1) ADDNewDomain parameter to parental/website-filters.asp or (2) VmTracerouteHos... Read more
- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0081
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via t... Read more
- Published: Feb. 20, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5799
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.2 allows remote attackers to affect integrity via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2901
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requireme... Read more
Affected Products : tomcat- Published: Jan. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-34801
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.... Read more
Affected Products : build_notifications- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024