Latest CVE Feed
-
4.3
MEDIUMCVE-2009-1380
Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via... Read more
Affected Products : jboss_enterprise_application_platform- Published: Dec. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2059
Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4891
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this infor... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4000
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via ... Read more
Affected Products : fckeditor- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2008
Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : performance_insight- Published: May. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4972
Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sys_solution_id, (2) sys_requesttype_id, (3) sys_problem_desc, (4) sys_solution_desc, (5) sys_problemsumm... Read more
Affected Products : helpbox- Published: Dec. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6043
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.... Read more
- Published: Nov. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-9894
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker... Read more
- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8509
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that ... Read more
Affected Products : bugzilla- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8488
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.... Read more
Affected Products : office- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5460
Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification.... Read more
Affected Products : snorby- Published: Jul. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8336
Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role and permission" information via unspecified vectors.... Read more
- Published: Apr. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-1000395
Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses i... Read more
Affected Products : jenkins- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8309
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."... Read more
Affected Products : cherrymusic- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-6099
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability."... Read more
Affected Products : .net_framework- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2963
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonst... Read more
Affected Products : paperclip- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-37218
Missing Authorization vulnerability in WordPress Page Builder Sandwich Team Page Builder Sandwich – Front-End Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Builder Sandwich – Front-End Page Bu... Read more
Affected Products : page_builder_sandwich- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2015-2620
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2612
Unspecified vulnerability in the Siebel Core - Server OM Svcs component in Oracle Siebel CRM 8.1.1, 8.2.2, and 15.0 allows remote attackers to affect confidentiality via vectors related to LDAP Security Adapter.... Read more
Affected Products : siebel_crm- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-36589
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.... Read more
Affected Products :- Published: Jun. 13, 2024
- Modified: Nov. 25, 2024