Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10084
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contribut... Read more
- Published: Nov. 05, 2024
- Modified: Jul. 11, 2025
-
4.3
MEDIUMCVE-2006-4881
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-47858
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint... Read more
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8117
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.... Read more
Affected Products : nextcloud_server- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32728
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.11.0. ... Read more
Affected Products : paid_membership_subscriptions- Published: Apr. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43269
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.... Read more
Affected Products : backup_and_restore_wordpress- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2013-6794
Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script or HTML via the Location field. NOTE: the provenance of this information is unknown; the details are obt... Read more
Affected Products : olat- Published: Nov. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9561
Cross-site scripting (XSS) vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the post parameter.... Read more
Affected Products : softbb- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5232
Cross-site scripting (XSS) vulnerability in the Quickl Form component for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0079
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.... Read more
Affected Products : opensso- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-20552
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X... Read more
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-30943
Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data of Bulletin.... Read more
Affected Products : garoon- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUM- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1325
The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on the 'ajax_cancel_review' function.... Read more
Affected Products : woomotiv- Published: Mar. 20, 2024
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6645
Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files.... Read more
Affected Products : visualsentinel- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3074
Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.... Read more
Affected Products : firefox- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-40388
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. Safari may save photos to an unprotected location.... Read more
Affected Products : macos- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-5427
Norton Antivirus in Norton Internet Security 15.5.0.23 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to c... Read more
Affected Products : norton_internet_security_2008- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1927
Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.... Read more
Affected Products : cmailserver- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4341
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.... Read more
Affected Products : moodle- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025