Latest CVE Feed
-
4.3
MEDIUMCVE-2024-0809
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Jan. 24, 2024
- Modified: May. 15, 2025
-
4.3
MEDIUMCVE-2014-0620
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web script or HTML via the (1) ADDNewDomain parameter to parental/website-filters.asp or (2) VmTracerouteHos... Read more
- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6179
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_service_registry_and_repository- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5983
Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php.... Read more
Affected Products : guppy- Published: Feb. 06, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27768
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.... Read more
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6690
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and... Read more
Affected Products : prime_collaboration- Published: Dec. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-41900
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to r... Read more
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27765
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application... Read more
- Published: Dec. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6702
The management implementation on Cisco ONS 15454 controller cards with software 9.8 and earlier allows remote attackers to cause a denial of service (card reset) via crafted packets, aka Bug ID CSCtz50902.... Read more
- Published: Dec. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5991
The displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to obtain sensitive information by leveraging incorrect handling of error-log output.... Read more
- Published: Nov. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7110
Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an... Read more
Affected Products : transifex- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6005
Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button.... Read more
Affected Products : dezie- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-42453
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2497
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus php solaris +2 more products- Published: Mar. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-27767
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most... Read more
- Published: Dec. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6010
Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Attachment field title."... Read more
- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6711
Cross-site scripting (XSS) vulnerability in the product-creation administrative page in Cisco WebEx Sales Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul25540.... Read more
Affected Products : webex_sales_center- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27761
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch ... Read more
- Published: Dec. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6009
CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet.... Read more
Affected Products : open-xchange_appsuite- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1595
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.... Read more
Affected Products : rdesktop- Published: May. 24, 2011
- Modified: Apr. 11, 2025