Latest CVE Feed
-
4.3
MEDIUMCVE-2009-3539
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.... Read more
Affected Products : ultra_classifieds_pro- Published: Oct. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-5205
Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links parameter.... Read more
Affected Products : rapidleech- Published: Oct. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3509
Cross-site scripting (XSS) vulnerability in admin/admin_index.php in CJ Dynamic Poll PRO 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : cj_dynamic_poll- Published: Oct. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10474
A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.... Read more
Affected Products : global_post_script- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4299
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.... Read more
Affected Products : linux_kernel aix hp-ux sterling_b2b_integrator solaris sterling_file_gateway windows i- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2082
Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web script or HTML via the module parameter, which leaks the path in an error message.... Read more
Affected Products : siteman- Published: May. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1627
feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.... Read more
Affected Products : phpbb- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6328
Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to injec... Read more
Affected Products : websphere_portal- Published: Dec. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6486
Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are o... Read more
Affected Products : lineshout- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-27940
This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.... Read more
Affected Products : apple_tv- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-5023
Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.... Read more
Affected Products : pligg_cms- Published: Dec. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1225
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.... Read more
Affected Products : turnkey_ebook_store- Published: Apr. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-7417
Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery... Read more
Affected Products : ipcop- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-0063
Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : brightmail_gateway_appliance- Published: Apr. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-2091
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.... Read more
Affected Products : garoon- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2019-3851
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.... Read more
- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-11282
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users ... Read more
- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5587
Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto link.... Read more
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-3844
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance s... Read more
Affected Products : prime_collaboration_assurance- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-4408
Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to inject arbitrary web script or HTML via crafted BBcode (1) img or (2) url tags, which are n... Read more
- Published: Dec. 23, 2009
- Modified: Apr. 09, 2025