Latest CVE Feed
-
4.3
MEDIUMCVE-2015-0655
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- Published: Feb. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20730
Improper access control vulnerability in WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allows an attacker to obtain configuration information via unspecified vectors.... Read more
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1052
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web script or HTML via the result parameter to upload_files/pk/include.php.... Read more
Affected Products : phpkit- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-8811
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.... Read more
Affected Products : bludit- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-35972
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.... Read more
Affected Products : yzmcms- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-25930
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerab... Read more
- Published: May. 20, 2021
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2009-3067
Cross-site scripting (XSS) vulnerability in index.php in Reservation Manager allows remote attackers to inject arbitrary web script or HTML via the resman_startdate parameter.... Read more
Affected Products : reservation_manager- Published: Sep. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7092
Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web script or HTML via a Javascript event in the (1) url, (2) PageName, and (3) title parameters in a CustomBookMarkLink a... Read more
Affected Products : affinium_campaign- Published: Aug. 26, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-0305
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or doma... Read more
Affected Products : netweaver_process_integration- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2002-2376
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue migh... Read more
Affected Products : e-guest- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-6611
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-mi... Read more
- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4832
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during a... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-6490
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.... Read more
Affected Products : series_one_cms- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2490
Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input."... Read more
Affected Products : kj_imagelightbox2- Published: May. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7133
Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to thumber.php,... Read more
Affected Products : easyimagecatalogue- Published: Sep. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3187
Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : saa- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-0589
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2669
Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.... Read more
Affected Products : orbis_cms- Published: Jul. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3448
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.... Read more
Affected Products : shopping_cart- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-11631
Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notifications via crafted Bluetooth Low Energy (BLE) traffic.... Read more
- Published: May. 31, 2018
- Modified: Nov. 21, 2024