Latest CVE Feed
-
4.3
MEDIUM- Published: May. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3184
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demon... Read more
Affected Products : vbulletin- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0748
A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.... Read more
Affected Products : firefox- Published: Jan. 23, 2024
- Modified: Jun. 11, 2025
-
4.3
MEDIUMCVE-2019-4603
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user. IBM X-Force ID: 168295.... Read more
Affected Products : rational_quality_manager- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-40692
Insufficient capability checks made it possible for teachers to download users outside of their courses.... Read more
Affected Products : moodle- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0639
Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated... Read more
Affected Products : mybulletinboard- Published: Feb. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2766
Cross-site scripting (XSS) vulnerability in Xigla Absolute Image Gallery XE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) admin/search.asp and (2) gallery.asp.... Read more
Affected Products : absolute_image_gallery_xe- Published: Jun. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2777
Cross-site scripting (XSS) vulnerability in Ortro before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : ortro- Published: Jun. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2797
Cross-site scripting (XSS) vulnerability in MainLayout.do in ManageEngine OpUtils 5.0 allows remote attackers to inject arbitrary web script or HTML via the hostName parameter, when viewing an SNMP graph. NOTE: the provenance of this information is unkno... Read more
- Published: Jun. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0978
Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and ... Read more
Affected Products : argosoft_mail_server- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-3779
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action.... Read more
Affected Products : five_star_review_script- Published: Aug. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-4330
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.... Read more
Affected Products : security_guardium_big_data_intelligence- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3101
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_p... Read more
Affected Products : vtiger_crm- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-1107
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the se... Read more
Affected Products : java- Published: Mar. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3088
Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category action to index.php.... Read more
Affected Products : kasseler_cms- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-11997
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, a... Read more
Affected Products : guacamole- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4411
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658.... Read more
Affected Products : cognos_controller- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3098
Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.... Read more
Affected Products : fuzzylime_cms- Published: Sep. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3448
Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.... Read more
Affected Products : csphonebook- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-1754
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.... Read more
Affected Products : moodle- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024