Latest CVE Feed
-
4.3
MEDIUMCVE-2020-8996
AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.... Read more
Affected Products : anyshare_cloud- Published: Feb. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2638
Cross-site scripting (XSS) vulnerability in SmallPICT.cgi in SmallPICT before 2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : smallpict- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2644
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2642.... Read more
- Published: Jul. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1161
Cross-site scripting (XSS) vulnerability in call_entry.php in Call Center Software 0,93 allows remote attackers to inject arbitrary web script or HTML via the problem_desc parameter, as demonstrated by the ONLOAD attribute of a BODY element.... Read more
Affected Products : call_center_software- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2669
Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) c... Read more
Affected Products : pre_shopping_mall- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-0447
The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_all_cache function in versions up to, and including, 3.0.12.1. This makes it possible for authenticated attackers, with subscr... Read more
Affected Products : my_youtube_channel- Published: Jan. 23, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0374
Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.... Read more
- Published: Jan. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3954
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell meta... Read more
- Published: Jul. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-36543
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacke... Read more
Affected Products : seeddms- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1475
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) ... Read more
Affected Products : my_little_forum- Published: Feb. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4771
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group pa... Read more
Affected Products : subrion_cms- Published: Oct. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7258
Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "displaying group DN and entry data in group administration UI."... Read more
Affected Products : web2ldap- Published: Jan. 03, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0984
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain pas... Read more
- Published: Apr. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-40443
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php... Read more
Affected Products : computer_laboratory_management_system- Published: Nov. 13, 2024
- Modified: Apr. 16, 2025
-
4.3
MEDIUMCVE-2024-32522
Missing Authorization vulnerability in Jaed Mosharraf & Pluginbazar Team Open Close WooCommerce Store.This issue affects Open Close WooCommerce Store: from n/a through 4.9.1. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-39918
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. Input of the `ImageId` in the code is not sanitized and may lead to path traversal. T... Read more
Affected Products :- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36800
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected version... Read more
Affected Products : jira_service_management- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5343
Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.... Read more
Affected Products : feng_office- Published: Aug. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-51667
Missing Authorization vulnerability in David de Boer Paytium.This issue affects Paytium: from n/a through 4.4.10.... Read more
Affected Products : paytium- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
4.3
MEDIUMCVE-2022-35204
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.... Read more
Affected Products : vite- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024