Latest CVE Feed
-
4.3
MEDIUMCVE-2010-4971
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.... Read more
- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13208
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more
Affected Products : wp_google_map- Published: Feb. 15, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2013-3675
The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via c... Read more
Affected Products : ffmpeg- Published: Jun. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4388
Cross-site scripting (XSS) vulnerability in the ListMan (nl_listman) extension 1.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-1399
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected s... Read more
Affected Products : unified_communications_manager- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0274
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vec... Read more
- Published: Jan. 24, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4544
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : facil_helpdesk- Published: Jan. 04, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-3474
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality via vectors related to Security.... Read more
Affected Products : business_intelligence_publisher- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0242
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving a URL that contains a username.... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2408
Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4505
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.... Read more
- Published: Mar. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4522
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : advantech_webaccess- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4446
Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : phpinstantgallery- Published: Dec. 29, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTML via the pa parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : million_pixel_script- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4985
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.... Read more
Affected Products : notes_management_system- Published: Nov. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-5005
Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileCommentTextArea parameter. NOTE: the provenance of this information is unknown; ... Read more
Affected Products : photoz- Published: Nov. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1454
ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by cert... Read more
Affected Products : php- Published: Mar. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-39886
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0034
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4469
Multiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) archiv parameter, and the (3) subcat parameter.... Read more
Affected Products : phppowercards- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025