Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2046
Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter.... Read more
Affected Products : sitexs_cms- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-6731
The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscrib... Read more
- Published: May. 02, 2024
- Modified: Mar. 05, 2025
-
4.3
MEDIUMCVE-2008-1953
Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is u... Read more
Affected Products : site_designer- Published: Apr. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2043
Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter to frontend/x2/cron/editcronsimple.html, and perform various administrative... Read more
Affected Products : cpanel- Published: May. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4545
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-mid... Read more
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-1917
Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location paramet... Read more
Affected Products : amfphp- Published: Apr. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4883
Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames."... Read more
Affected Products : tftpd32- Published: Nov. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0102
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.... Read more
Affected Products : tinyphpforum- Published: Jan. 06, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-5967
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin ... Read more
- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-20255
A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP reques... Read more
Affected Products : webex_meetings- Published: May. 21, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2008-2000
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.... Read more
Affected Products : safari- Published: Apr. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1960
Cross-site scripting (XSS) vulnerability in cgi-bin/contray/search.cgi in ContRay 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained s... Read more
Affected Products : contray- Published: Apr. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2006
Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit i... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-6727
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords... Read more
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-0112
Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.... Read more
Affected Products : enhanced_simple_php_gallery- Published: Jan. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4672
Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.... Read more
Affected Products : simple_image_editor- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1987
Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : encapsgallery- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1977
Cross-site request forgery (CSRF) vulnerability in the Internationalization (i18n) Drupal module 5.x before 5.x-2.3 and 5.x-1.1, and 6.x before 6.x-1.0 beta 1, allows remote attackers to change node translation relationships via unspecified vectors.... Read more
- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3314
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script ... Read more
Affected Products : egroupware- Published: Sep. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-5937
The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the ... Read more
Affected Products : micropayments- Published: Jun. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Request Forgery