Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2871
Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this infor... Read more
Affected Products : pegames- Published: Jun. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2776
Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely ... Read more
Affected Products : dt_centrepiece- Published: Jun. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2842
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.... Read more
Affected Products : cms- Published: Jun. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0649
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dataparksearch- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-6868
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.*... Read more
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-3990
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can b... Read more
Affected Products : harbor- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-24695
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, un... Read more
Affected Products : bluetooth_core_specification- Published: Jun. 02, 2023
- Modified: Jan. 10, 2025
-
4.3
MEDIUMCVE-2019-3981
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.... Read more
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10903
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2165
Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : building_broadband_service_manager- Published: May. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0210
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.... Read more
Affected Products : trackpoint_nx- Published: Jan. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-3233
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wordpress- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3184
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demon... Read more
Affected Products : vbulletin- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2162
Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page.... Read more
Affected Products : e-mail_security- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-6870
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.... Read more
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-1999-0877
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.... Read more
Affected Products : internet_explorer- Published: Oct. 01, 1999
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-4288
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160631.... Read more
Affected Products : maximo_anywhere- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1566
Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine Applications Manager 8.x allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are ob... Read more
- Published: Mar. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2200
Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 param... Read more
Affected Products : maian_weblog- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3244
The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read.... Read more
- Published: Jul. 21, 2008
- Modified: Apr. 09, 2025