Latest CVE Feed
-
4.3
MEDIUMCVE-2011-5307
Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : photosmash- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-12201
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers,... Read more
Affected Products : hash_form- Published: Dec. 12, 2024
- Modified: Feb. 27, 2025
-
4.3
MEDIUMCVE-2009-4497
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program.... Read more
- Published: Jan. 07, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0357
Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web... Read more
Affected Products : lotus_web_content_management- Published: Jan. 20, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4518
Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via an inserted node.... Read more
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-14708
Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker ... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0475
Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.... Read more
Affected Products : firewall- Published: May. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4433
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.ph... Read more
Affected Products : isupport- Published: Dec. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5752
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via uns... Read more
- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-22114
User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.... Read more
Affected Products : zabbix- Published: Aug. 12, 2024
- Modified: Dec. 04, 2024
-
4.3
MEDIUMCVE-2009-4570
Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.... Read more
Affected Products : phpshop- Published: Jan. 05, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0452
Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vec... Read more
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12237
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justified_gallery_callback function. This makes it possible for... Read more
Affected Products : photo_gallery_slideshow_\&_masonry_tiled_gallery- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Server-Side Request Forgery
-
4.3
MEDIUMCVE-2010-1235
Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to trigger the omission of a download warning dialog via unknown vectors.... Read more
Affected Products : chrome- Published: Apr. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2885
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allows remote attackers to inject arbitrary web script or HTML via vectors related to WebHelp generation with RoboHelp for Word.... Read more
- Published: Oct. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-5850
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2844
Cross-site scripting (XSS) vulnerability in news_show.php in Newanz NewsOffice 2.0.18 allows remote attackers to inject arbitrary web script or HTML via the n-cat parameter.... Read more
Affected Products : newsoffice- Published: Jul. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2886
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4473
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote attackers to inject arbitrary web script or HTML via the (1) css... Read more
Affected Products : cms4000.net- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2846
Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the afmsg parameter to index.php.... Read more
- Published: Jul. 25, 2010
- Modified: Apr. 11, 2025