Latest CVE Feed
-
4.3
MEDIUMCVE-2003-0481
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.... Read more
Affected Products : tutos- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1735
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : sympa- Published: Aug. 21, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-1413
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.... Read more
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-1730
Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php... Read more
Affected Products : mantis- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-29538
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for ... Read more
- Published: Jun. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-5893
In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Client responds to authentication requests over HTTP while sending probes for captive portal detection.... Read more
- Published: Apr. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-23850
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : synopsys_coverity- Published: Feb. 15, 2023
- Modified: Mar. 18, 2025
-
4.3
MEDIUMCVE-2004-2015
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.... Read more
Affected Products : webct- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-23899
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Extensions For CF7 plugin <= 2.0.8 versions leads to arbitrary plugin activation.... Read more
Affected Products : extensions_for_cf7- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2001
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead ... Read more
Affected Products : gitlab- Published: Jun. 07, 2023
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2018-1000862
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the... Read more
- Published: Dec. 10, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-20937
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1021
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8123.... Read more
Affected Products : edge- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-1776
When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 and prior versions... Read more
Affected Products : otrs- Published: Jul. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2004-2038
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.... Read more
Affected Products : land_down_under- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-27920
Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system date/time of the af... Read more
- Published: May. 23, 2023
- Modified: Jan. 31, 2025
-
4.3
MEDIUMCVE-2020-6371
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Di... Read more
- Published: Oct. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2555
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authen... Read more
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1484
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.... Read more
Affected Products : ie- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1544
Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.... Read more
Affected Products : jspwiki- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025