Latest CVE Feed
-
4.3
MEDIUMCVE-2008-6876
Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037.... Read more
Affected Products : espartenaires- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-3315
Vulnerability in the PeopleSoft Enterprise HCM ePerformance component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network acces... Read more
Affected Products : peoplesoft_enterprise_human_capital_management_eperformance- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-4948
Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4910
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CS... Read more
- Published: Jun. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4894
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in PunBB before 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) password or (2) e-mail.... Read more
Affected Products : punbb- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0872
Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) captchaField, (2) email, (3) form_name, (4) password, (5) realname, (6) repeatPassword, or (7) userna... Read more
Affected Products : oxwall- Published: Mar. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5091
Unspecified vulnerability in the Oracle Agile Product Supplier Collaboration for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality via unknown vectors related to Supplier Portal.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4684
Cross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the sign parameter.... Read more
Affected Products : ezodiak- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4682
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.... Read more
Affected Products : good\/bad_vote- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4647
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit... Read more
Affected Products : secure_file_transfer_appliance- Published: Feb. 19, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-43933
Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.... Read more
Affected Products : wpmobile.app- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2012-4909
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.... Read more
- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-13439
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 4.4.9. This makes it possible for authenticated attackers,... Read more
Affected Products : team- Published: Feb. 15, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-6340
Cross-site scripting (XSS) vulnerability in the Vox populi (mv_vox_populi) extension 0.3.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-27525
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 ... Read more
Affected Products : superset- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-38482
A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.... Read more
Affected Products : hopex- Published: Jan. 10, 2023
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2008-6238
Cross-site scripting (XSS) vulnerability in archive/savedqueries/savequeryfinish.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the name parameter.... Read more
Affected Products : openedit_digital_asset_management- Published: Feb. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6063
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Tempo... Read more
Affected Products : word- Published: Feb. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4876
Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly ha... Read more
Affected Products : voip841_dect_phone- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025