Latest CVE Feed
-
4.3
MEDIUMCVE-2019-15002
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-8103
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for u... Read more
Affected Products : wpematico_rss_feed_fetcher- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-2670
IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to workflow feature of OpenPages. An authenticated user is able to obtain certain information abo... Read more
- Published: Jul. 09, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2014-5172
Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : hana- Published: Jul. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-1753
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.... Read more
Affected Products : security_key_lifecycle_manager- Published: Oct. 08, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1642
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'postin... Read more
- Published: Mar. 13, 2024
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-6164
Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : hostadmin- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-38977
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site t... Read more
Affected Products : linux_kernel aix security_key_lifecycle_manager windows security_guardium_key_lifecycle_manager- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3813
PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter.... Read more
Affected Products : noboard_module- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-4797
Cross-site scripting (XSS) vulnerability in tag.php in CloudNine Interactive CJ Tag Board 3.0 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a url BBcode tag in the cjmsg parameter.... Read more
Affected Products : cj_tag_board- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4923
Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter.... Read more
Affected Products : esyndicat_portal_system- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-4744
Cross-site scripting (XSS) vulnerability in the Contact module in Exponent CMS 0.97-GA20090213 allows remote attackers to inject arbitrary web script or HTML via the email parameter. NOTE: the provenance of this information is unknown; the details are ob... Read more
- Published: Mar. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4464
Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : active_business_directory- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5516
Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters to wakka.php.... Read more
Affected Products : wikini- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5599
Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE: it is likely that this issue overlaps one of t... Read more
Affected Products : apex- Published: Oct. 28, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1919
Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : livre_d_or_livor- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1988
Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : phpecho_cms- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1989
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NO... Read more
Affected Products : dotclear- Published: Apr. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4461
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) contact.php, (2) login.php, and (3) search.php.... Read more
Affected Products : flatpress- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2206
Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading "<"<" in the ripeformpost parameter.... Read more
Affected Products : ripe_website_manager- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025