Latest CVE Feed
-
4.3
MEDIUMCVE-2020-36473
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.... Read more
- Published: Aug. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-35406
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.... Read more
Affected Products : burp_suite- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-3763
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact... Read more
Affected Products : amq_broker- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0789
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2121
Opera 9.52 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.... Read more
Affected Products : opera_browser- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-0055
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."... Read more
Affected Products : internet_explorer- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1754
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to injec... Read more
- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3752
Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect integrity via vectors related to Service Management Facility (SMF).... Read more
- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4424
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-18348
Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2032
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm ... Read more
Affected Products : resin- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0653
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."... Read more
- Published: Sep. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2645
HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors.... Read more
Affected Products : systems_insight_manager- Published: Oct. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0552
Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashb... Read more
Affected Products : im_manager- Published: Oct. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0550
Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token p... Read more
Affected Products : endpoint_protection- Published: Aug. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4067
Walrus in Eucalyptus before 3.2.2 allows remote attackers to cause a denial of service (memory, thread, and CPU consumption) via a crafted XML message containing a DTD, as demonstrated by a bucket-logging request.... Read more
Affected Products : eucalyptus- Published: Sep. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-9979
The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-le... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2013-3671
The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via c... Read more
Affected Products : ffmpeg- Published: Jun. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-8778
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2013-3673
The gif_decode_frame function in gifdec.c in libavcodec in FFmpeg before 1.2.1 does not properly manage the disposal methods of frames, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via craft... Read more
Affected Products : ffmpeg- Published: Jun. 10, 2013
- Modified: Apr. 11, 2025