Latest CVE Feed
-
4.3
MEDIUMCVE-2002-1335
Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.... Read more
Affected Products : w3m- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4903
Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.... Read more
Affected Products : typo- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5475
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.... Read more
Affected Products : request_tracker- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-6162
Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a category action.... Read more
Affected Products : fmdeluxe- Published: Nov. 29, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5335
Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.... Read more
Affected Products : firefox- Published: Oct. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6467
Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site, as exploited in the wild in November 2012.... Read more
Affected Products : opera_browser- Published: Jan. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10130
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms ... Read more
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5310
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or ca... Read more
Affected Products : android- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-52060
A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.... Read more
Affected Products : gestsup- Published: Feb. 13, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2015-5571
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the... Read more
Affected Products : android linux_kernel flash_player mac_os_x windows air air_sdk air_sdk_\&_compiler- Published: Sep. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5824
The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati... Read more
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-6121
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-5980
Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).... Read more
Affected Products : eggblog- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5303
Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.... Read more
Affected Products : snewscms_rus- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6274
Multiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) day or (2) year parameter.... Read more
Affected Products : bcoos- Published: Dec. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-3740
Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)... Read more
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5339
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5291
Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : db_manager- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-38174
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability... Read more
Affected Products : edge_chromium- Published: Dec. 07, 2023
- Modified: Jan. 01, 2025
-
4.3
MEDIUMCVE-2024-6389
An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permi... Read more
Affected Products : gitlab- Published: Sep. 12, 2024
- Modified: Nov. 21, 2024