Latest CVE Feed
-
4.3
MEDIUMCVE-2009-3004
Avant Browser 11.7 Builds 35 and 36 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which... Read more
Affected Products : avant_browser- Published: Aug. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-4554
Cross-site scripting (XSS) vulnerability in templates/download.php in the SS Downloads plugin before 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : ss_downloads- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4541
Cross-site scripting (XSS) vulnerability in shortcode-generator/preview-shortcode-external.php in the OMFG Mobile Pro plugin 1.1.26 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.... Read more
Affected Products : omfg_mobile- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-3127
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : lucidcms- Published: Oct. 04, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-3014
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote ... Read more
- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-6852
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system file... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4307
Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 and earlier allow remote attackers to inject arbitrary web script or HTML via the next parameter to (1) addaddress.php, (2) editshipdetails.php, (3) register.php, or (4) login.php in sec... Read more
Affected Products : storesprite- Published: Aug. 13, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6308
Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several thi... Read more
Affected Products : livestate_agent_for_windows- Published: Dec. 06, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3921
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.... Read more
Affected Products : awstats_totals- Published: Sep. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3110
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via i... Read more
- Published: Jul. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2522
Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP... Read more
Affected Products : knowledge- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-3303
Multiple cross-site scripting (XSS) vulnerabilities in pm.php in DeluxeBB 1.07 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) to parameters.... Read more
Affected Products : deluxebb- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-15392
A vulnerability in the DHCP service of Cisco Industrial Network Director could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of DHCP lease requests. An attacker coul... Read more
Affected Products : industrial_network_director- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3842
Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise Filter before 2.0.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this may be the same as CVE-2007-2970.... Read more
Affected Products : r3000_enterprise_filter- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3087
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m parameter in (a) common/galleries.asp; (6) aid, (7) ... Read more
Affected Products : ezgallery- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-25671
A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a partial denial-of-service, prevent... Read more
Affected Products : rwg1.m12_firmware rwg1.m12d_firmware rwg1.m8_firmware rwg1.m12 rwg1.m12d rwg1.m8- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0269
A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissiv... Read more
Affected Products : digital_network_architecture_center- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-4660
Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal 5.0.7961 allows remote attackers to inject arbitrary web script or HTML via the id parameter to iframe.php.... Read more
Affected Products : enhanced_sql_portal- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-3003
details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant from another vulnerability, since this vector also produces... Read more
Affected Products : easy_ad-manager- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-1220
Cybozu Garoon before 4.2.2 does not properly restrict access.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025