Latest CVE Feed
-
4.3
MEDIUMCVE-2010-4329
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or... Read more
Affected Products : phpmyadmin- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4116
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by s... Read more
Affected Products : unified_computing_system- Published: Oct. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5911
Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.... Read more
Affected Products : b2evolution- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4088
The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769.... Read more
Affected Products : unified_computing_system- Published: Sep. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4144
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a cr... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6043
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.... Read more
- Published: Nov. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-21233
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 31, 2024
-
4.3
MEDIUMCVE-2012-5913
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.... Read more
- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4072
The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key... Read more
Affected Products : unified_computing_system- Published: Sep. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5949
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) bi... Read more
Affected Products : tririga_application_platform- Published: Apr. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0068
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.... Read more
Affected Products : wireshark- Published: Apr. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5956
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrat... Read more
Affected Products : manageengine_assetexplorer- Published: Dec. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6132
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.... Read more
Affected Products : roundup- Published: Apr. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4043
Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5 allows remote attackers to inject arbitrary web scri... Read more
- Published: Jul. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5977
Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remot... Read more
- Published: Jan. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-28166
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrit... Read more
- Published: Aug. 13, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2024-21206
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network ... Read more
Affected Products : enterprise_command_center_framework- Published: Oct. 15, 2024
- Modified: Jun. 23, 2025
-
4.3
MEDIUMCVE-2012-4018
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.... Read more
Affected Products : mywebsearch- Published: Oct. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4016
The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.... Read more
- Published: Sep. 28, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4013
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file... Read more
Affected Products : kunai_browser_for_remote_service- Published: Sep. 14, 2012
- Modified: Apr. 11, 2025