Latest CVE Feed
-
4.3
MEDIUMCVE-2021-29853
IBM Planning Analytics 2.0 could expose information that could be used to to create attacks by not validating the return values from some methods or functions. IBM X-Force ID: 205529.... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2082
Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web script or HTML via the module parameter, which leaks the path in an error message.... Read more
Affected Products : siteman- Published: May. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2401
Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post.... Read more
Affected Products : phpecho_cms- Published: Jul. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-27940
This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.... Read more
Affected Products : apple_tv- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-34626
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.... Read more
Affected Products : wp-upload-restriction- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3832
Cross-site scripting (XSS) vulnerability in the Documents component in ownCloud Server 6.0.x before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.... Read more
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-6270
Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx.... Read more
Affected Products : absolute_news_manager.net- Published: Dec. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1620
Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name1, (2) email, or (3) cmt parameter.... Read more
Affected Products : hiox_guest_book- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-1847
The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : rotating_posts- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-1225
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.... Read more
Affected Products : turnkey_ebook_store- Published: Apr. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1612
Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
- Published: Jan. 30, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1627
feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.... Read more
Affected Products : phpbb- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1048
Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. NOTE: some of these details are o... Read more
Affected Products : business_portal- Published: Mar. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5799
Cross-site scripting (XSS) vulnerability in the Wir ber uns (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-15577
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.... Read more
Affected Products : gitlab- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2331
Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be res... Read more
Affected Products : serendipity- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-1796
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity ... Read more
- Published: Jul. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4236
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : ecommerce- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6390
Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.... Read more
- Published: Dec. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4226
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string t... Read more
Affected Products : quick_post_widget- Published: Sep. 03, 2014
- Modified: Apr. 12, 2025