Latest CVE Feed
-
4.3
MEDIUMCVE-2023-2352
The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.4. This is due to missing or incorrect nonce validation on the chp_abd_action function. This makes it possible for unauthenti... Read more
Affected Products : chp_ads_block_detector- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2495
The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs... Read more
Affected Products : greeklish-permalink- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1585
Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.... Read more
Affected Products : weblog_expert- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-1960
Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.... Read more
Affected Products : protector_system- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1930
Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.... Read more
Affected Products : php-nuke- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1586
Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.... Read more
Affected Products : webexpert- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-0065
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-201... Read more
Affected Products : edge- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-24449
Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins... Read more
Affected Products : pwauth_security_realm- Published: Jan. 26, 2023
- Modified: Apr. 02, 2025
-
4.3
MEDIUMCVE-2004-1657
Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.... Read more
Affected Products : dasblog- Published: Sep. 01, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2021-1477
A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcem... Read more
- Published: Apr. 29, 2021
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2021-1354
A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM). This vulnerability is due t... Read more
Affected Products : unified_computing_system_central_software- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1669
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Sear... Read more
- Published: Sep. 10, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-28360
An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the user.... Read more
Affected Products : brave- Published: May. 11, 2023
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2023-24455
Jenkins visualexpert Plugin 1.3 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Item/Configure permission to check for the existence of an attacker-specified file path on the Jenkins contro... Read more
Affected Products : visual_expert- Published: Jan. 26, 2023
- Modified: Apr. 02, 2025
-
4.3
MEDIUMCVE-2021-1367
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient inp... Read more
Affected Products : nx-os nexus_92300yc_switch nexus_92304qc_switch nexus_9236c_switch nexus_9272q_switch nexus_93108tc-ex_switch nexus_93108tc-fx-24 nexus_93120tx nexus_93128tx nexus_9316d-gx +33 more products- Published: Feb. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-5525
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied tr... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +3 more products- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-5333
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.... Read more
Affected Products : archer- Published: May. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1000399
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.... Read more
Affected Products : jenkins- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1000400
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of It... Read more
Affected Products : jenkins- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-15733
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.... Read more
Affected Products : gitlab- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024