Latest CVE Feed
-
4.3
MEDIUMCVE-2024-21665
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. ... Read more
Affected Products : e-commerce_framework- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3396
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh... Read more
- Published: Jun. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2193
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.... Read more
Affected Products : hbase- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-2287
Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.... Read more
Affected Products : uploader- Published: Apr. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-13852
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbit... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2005-1189
Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.... Read more
Affected Products : webcamxp_pro- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-2179
X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) b... Read more
Affected Products : x_display_manager- Published: Dec. 27, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-24719
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9. ... Read more
Affected Products :- Published: Mar. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5255
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the ie parameter to the /search URI.... Read more
Affected Products : mini_search_appliance- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-3648
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.... Read more
- Published: Nov. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1944
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.... Read more
Affected Products : ilch_cms- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3376
Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490.... Read more
Affected Products : video_surveillance_operations_manager- Published: Jun. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4728
The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition 16.0.0.388 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted QPW file... Read more
Affected Products : quattro_pro_x6- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-0240
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."... Read more
Affected Products : java_system_identity_manager- Published: Jan. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4488
libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers.... Read more
Affected Products : libgadu- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-2132
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."... Read more
- Published: Aug. 15, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6637
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE:... Read more
Affected Products : flash_player- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-24776
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions. ... Read more
- Published: Feb. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1228
Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.... Read more
Affected Products : jabber- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5432
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).... Read more
Affected Products : moodle- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025