Latest CVE Feed
-
4.3
MEDIUMCVE-2024-3127
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP r... Read more
Affected Products : gitlab- Published: Aug. 22, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2007-3516
Multiple cross-site scripting (XSS) vulnerabilities in kayit.asp in Gorki Online Santrac Sitesi allow remote attackers to inject arbitrary web script or HTML via the (1) kullanici, (2) posta, or (3) takim_adi parameter to uyeler.asp. NOTE: the provenance... Read more
Affected Products : santrac_sitesi- Published: Jul. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3844
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:... Read more
- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3941
Cross-site scripting (XSS) vulnerability in profile.php in Jasmine CMS 1.0_1 allows remote authenticated users to inject arbitrary web script or HTML via the profile_email parameter. NOTE: the provenance of this information is unknown; the details are ob... Read more
Affected Products : cms- Published: Jul. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3366
Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unk... Read more
Affected Products : cpanel- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4981
Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a docu... Read more
Affected Products : obedit- Published: Sep. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-41228
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to stea... Read more
Affected Products : esxi vcenter_server cloud_foundation telco_cloud_platform telco_cloud_infrastructure- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2007-3396
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.... Read more
Affected Products : kf_web_server- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3593
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflo... Read more
Affected Products : manageengine_netflow_analyzer- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3886
Cross-site scripting (XSS) vulnerability in default.asp in Element CMS allows remote attackers to inject arbitrary web script or HTML via the s parameter in a search pID action.... Read more
Affected Products : element_cms- Published: Jul. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5072
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.... Read more
Affected Products : simple_php_blog- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2819
Cross-site scripting (XSS) vulnerability in reportItem.do in Track+ 3.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the projId parameter.... Read more
Affected Products : track\+- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4481
Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).... Read more
Affected Products : blix- Published: Aug. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2825
Multiple cross-site scripting (XSS) vulnerabilities in ReadMsg.php in @Mail 5.02 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) links and (2) images.... Read more
Affected Products : atmail_webmail- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2993
Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to inject arbitrary web script or HTML via (1) user-created text fields; the (2) F05003, (3) F05005, and (4... Read more
Affected Products : interneserviceslosungen- Published: Jun. 04, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5012
Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to inject arbitrary web script or HTML via the author parameter. NOTE: the provenance of this information is unknown... Read more
Affected Products : phpwebgallery- Published: Sep. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.... Read more
Affected Products : moodle- Published: Apr. 25, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-2832
Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pat... Read more
Affected Products : call_manager- Published: May. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-49098
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_22h2 windows windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 windows_11_24h2 +1 more products- Published: Dec. 12, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2007-3496
Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, al... Read more
- Published: Jun. 29, 2007
- Modified: Apr. 09, 2025