Latest CVE Feed
-
4.3
MEDIUMCVE-2006-6547
Buffer overflow in the readAA function in read_aa.cpp in Winamp iPod Plugin (ml_ipod) 2.00 p19 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long tag in an audible.com audiobook (aa) f... Read more
Affected Products : winamp_ipod_plugin- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-3928
A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /actuator/heapdump of the component auth-server. The manipulation leads to infor... Read more
Affected Products :- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20730
Improper access control vulnerability in WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allows an attacker to obtain configuration information via unspecified vectors.... Read more
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-35279
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against... Read more
Affected Products : business_automation_workflow- Published: Nov. 03, 2022
- Modified: May. 02, 2025
-
4.3
MEDIUMCVE-2020-9077
HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing ... Read more
- Published: Jul. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-7080
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.... Read more
Affected Products : content_management_system- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-45349
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. ... Read more
Affected Products : betheme- Published: Mar. 25, 2024
- Modified: Jan. 31, 2025
-
4.3
MEDIUMCVE-2011-2408
Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : palm_webos- Published: Aug. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0132
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4207
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a submission.... Read more
- Published: Dec. 04, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2165
Multiple cross-site scripting (XSS) vulnerabilities in the Report Viewer in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4.x, 5.x, and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) portal, (2) fromDate, (3) toDate... Read more
Affected Products : drutt_mobile_service_delivery_platform- Published: Apr. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-4146
Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-2104
Directory traversal vulnerability in Orbit Downloader 3.0.0.4 and 3.0.0.5 allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the name attribute of a file element.... Read more
Affected Products : orbit_downloader- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-2209
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.... Read more
Affected Products : testcomplete_support- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-6173
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : clipshare- Published: Feb. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-22508
Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.... Read more
- Published: May. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3359
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.... Read more
Affected Products : match_agency_biz- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-5194
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than... Read more
- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5500
Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuj23320, CSCuj23324, CSCuj23333, and CSCuj23338... Read more
Affected Products : mediasense- Published: Sep. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1479
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.... Read more
Affected Products : creative_guestbook- Published: Mar. 16, 2007
- Modified: Apr. 09, 2025