Latest CVE Feed
-
4.3
MEDIUMCVE-2025-57885
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support allows Cross Site Request Forgery. This issue affects Fluent Support: from n/a through 1.9.1.... Read more
Affected Products : fluent_support- Published: Aug. 22, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2006-0461
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).... Read more
Affected Products : expressionengine- Published: Jan. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-39934
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1711
The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers ... Read more
- Published: Aug. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-39905
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with... Read more
Affected Products : gitlab- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39868
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.... Read more
Affected Products : gitlab- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4206
Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID para... Read more
Affected Products : aspplayground.net- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0498
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0365
Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.... Read more
Affected Products : xmb_forum- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0361
Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.... Read more
Affected Products : bit_5_blog- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3167
Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, which allows remote attackers to conduct cross-site scripti... Read more
Affected Products : mediawiki- Published: Oct. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0350
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.... Read more
Affected Products : eggblog- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-1824
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE... Read more
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-0246
Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.... Read more
Affected Products : download_tracker- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-38302
A certain software build for the Sharp Rouvo V device (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys) leaks the Wi-Fi MAC address and the Bluetooth MAC address to system properties that can be accessed by any local app on... Read more
Affected Products :- Published: Apr. 22, 2024
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2018-18355
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1857
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in... Read more
- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-0217
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error ... Read more
Affected Products : ultimate_auction- Published: Jan. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0156
Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.... Read more
Affected Products : foxrum- Published: Jan. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-57176
The rfpiped service on TCP port 555 in Ceragon Networks / Siklu Communication EtherHaul series (8010TX and 1200FX tested) Firmware 7.4.0 through 10.7.3 allows unauthenticated file uploads to any writable location on the device. File upload packets use wea... Read more
Affected Products :- Published: Sep. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authentication