Latest CVE Feed
-
4.3
MEDIUMCVE-2006-1428
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.... Read more
Affected Products : phpcoin- Published: Mar. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-5603
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors relate... Read more
Affected Products : flexcube_universal_banking- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0231
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.... Read more
Affected Products : financial_transaction_manager- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5706
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater t... Read more
Affected Products : coursemill_learning_management_system- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3135
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 5.1.1 Alpha 9 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to privatemessage/new/, (2) the folderid parameter to a private message in privatemessage/vi... Read more
Affected Products : vbulletin- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-7292
Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.... Read more
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-20892
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-9596
Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is enabled, and MK 3.0 VPU before 9.3.1 build 5.06.000.0, when Embedded Wi-Fi or Direct LAN is enabled, does not use encryption, which allows... Read more
- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2589
Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.... Read more
Affected Products : hutscripts_php_website_script- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2879
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings... Read more
- Published: Apr. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-4333
Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.... Read more
Affected Products : php_infoboard- Published: Sep. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1046
Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.... Read more
Affected Products : cognos_tm1- Published: Feb. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-0761
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack... Read more
Affected Products : clock_in_portal-_staff_\&_attendance_management- Published: May. 15, 2023
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2012-1209
Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.... Read more
Affected Products : fork_cms- Published: Feb. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2540
Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.... Read more
Affected Products : opera_browser- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-1087
The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack... Read more
Affected Products : wc_sales_notification- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
4.3
MEDIUMCVE-2014-6243
Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.... Read more
Affected Products : ewww_image_optimizer_plugin- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-20307
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.... Read more
Affected Products : virtual_traffic_manager- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2636
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_patio- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4547
Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary web script or HTML via the (1) main_... Read more
Affected Products : zen_cart- Published: Nov. 29, 2011
- Modified: Apr. 11, 2025