Latest CVE Feed
-
4.3
MEDIUMCVE-2007-1331
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q... Read more
Affected Products : eportfolio- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0902
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.... Read more
- Published: Feb. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-4103
The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() f... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0737
The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795.... Read more
Affected Products : unified_ip_phone_7960g- Published: Feb. 22, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-47813
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.... Read more
Affected Products : wing_ftp_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2014-0812
Cross-site scripting (XSS) vulnerability in KENT-WEB Joyful Note 2.8 and earlier, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 01, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-42934
SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2014-3274
Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be established, which allows man-in-the-middle attackers to obtain sensitive directory information by leveraging a network position between CTS an... Read more
Affected Products : telepresence_system_software- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2101
Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : navigate- Published: Feb. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7776
Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.... Read more
Affected Products : garoon- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2980
Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.... Read more
Affected Products : base- Published: Apr. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-4745
Cross-site scripting (XSS) vulnerability in emailFriend.asp in Uniwin eCart Professional 2.0.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : ecart_professional- Published: Oct. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4868
Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party... Read more
Affected Products : answer_me- Published: May. 11, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4447
The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet fi... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0533
Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta; and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related t... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6808
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.... Read more
Affected Products : zendto- Published: Dec. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-16567
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : team_concert- Published: Dec. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4594
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to cause a denial of service (memory consumption and HTTP-AS ... Read more
Affected Products : lotus_mobile_connect- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2172
Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the upd... Read more
Affected Products : ds4100 ds_storage_manager_host_software ds4200 ds4300 ds4400 ds4500 ds4700 ds4800 system_storage_dcs3700_storage_subsystem system_storage_ds3200 +8 more products- Published: Jun. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2788
The DNP3 Slave service in SUBNET Solutions SubSTATION Server 2.7.0033 and 2.8.0106 allows remote attackers to cause a denial of service (unhandled exception and process crash) via unspecified vectors.... Read more
Affected Products : substation_server- Published: Sep. 17, 2013
- Modified: Apr. 11, 2025