Latest CVE Feed
-
4.3
MEDIUMCVE-2018-20906
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5100
Cross-site scripting (XSS) vulnerability in the Static Methods since 2007 (div2007) extension before 0.10.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the t3lib_div::quoteJSvalue function.... Read more
Affected Products : static_methods- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-20892
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3301
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.... Read more
Affected Products : rdiffweb- Published: Sep. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2589
Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.... Read more
Affected Products : hutscripts_php_website_script- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-5566
Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the application's data via the applications 'E-mail' and 'Messages'.... Read more
Affected Products : garoon- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-5205
Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links parameter.... Read more
Affected Products : rapidleech- Published: Oct. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-2272
A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : elastest- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-4333
Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.... Read more
Affected Products : php_infoboard- Published: Sep. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-2408
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2540
Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.... Read more
Affected Products : opera_browser- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-0325
Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin sett... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-2273
A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : elastest- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0862
Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via un... Read more
Affected Products : tangocms- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-6243
Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.... Read more
Affected Products : ewww_image_optimizer_plugin- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-7242
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachabl... Read more
Affected Products : modxcms- Published: Sep. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-20307
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.... Read more
Affected Products : virtual_traffic_manager- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2636
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_patio- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-34803
Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2997
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action.... Read more
Affected Products : gravity_board_x- Published: Jul. 03, 2008
- Modified: Apr. 09, 2025