Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1877
Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter.... Read more
Affected Products : lpanel- Published: Jun. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1519
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.... Read more
Affected Products : clustering_engine- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1100
Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.... Read more
Affected Products : cyberdocs- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0801
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.... Read more
Affected Products : electronic_documentation- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-6672
Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote at... Read more
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2003-0446
Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the scrip... Read more
Affected Products : internet_explorer- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-6254
administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from co... Read more
Affected Products : cahier_de_textes- Published: Dec. 04, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-5756
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to de... Read more
Affected Products : open-xchange_appsuite- Published: Jun. 16, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2675
Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from ... Read more
Affected Products : php_image_gallery- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4905
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4052
Multiple cross-site scripting (XSS) vulnerabilities in Jease before 2.9, when creating a comment, allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, or (3) comment parameter.... Read more
Affected Products : jease- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-4409
The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for... Read more
Affected Products : woocommerce_etsy_integration- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2869
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated atta... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0158
MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.... Read more
Affected Products : iphone_os- Published: Mar. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7280
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a long string in a .m3u file.... Read more
Affected Products : hanso_player- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1442
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.... Read more
Affected Products : esafe panda_antivirus rising_antivirus f-secure_anti-virus sophos_anti-virus kaspersky_anti-virus quick_heal fortinet_antivirus avl_sdk gateway +1 more products- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3672
Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page.... Read more
Affected Products : dotclear- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2527
Cross-site scripting (XSS) vulnerability in view.php in ActualScripts ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite 2.78 and earlier allows remote attackers to in... Read more
Affected Products : actualanalyzer_lite actualanalyzer_gold actualanalyzer_pro actualanalyzer_server- Published: Jun. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2004-1954
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.... Read more
Affected Products : phprofession- Published: Apr. 21, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-4726
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 1... Read more
Affected Products : sterling_b2b_integrator- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024