Latest CVE Feed
-
4.3
MEDIUMCVE-2022-0371
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions starting from 14.6 before 14.6.4, all versions starting from 14.7 before 14.7.1. GitLab search may allow authenticated users to search other... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0925
Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : community_server- Published: Feb. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0890
Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.... Read more
Affected Products : webhost_manager- Published: Feb. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1443
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_password, (4... Read more
- Published: Mar. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-1189
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 that allowed for an unauthorised user to read the the approv... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1462
The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view ... Read more
- Published: Mar. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6977
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FreeTextBox allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.... Read more
Affected Products : freetextbox- Published: Feb. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6142
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE:... Read more
Affected Products : jaf_cms- Published: Nov. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6999
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.... Read more
Affected Products : deskpro- Published: Feb. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1238
Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.... Read more
Affected Products : office- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1504
Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HT... Read more
- Published: Mar. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1231
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php an... Read more
Affected Products : sqlitemanager- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1245
IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.... Read more
Affected Products : irfanview- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1234
Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (... Read more
Affected Products : sitex- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1239
Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.... Read more
Affected Products : excel- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6141
Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : vbtube- Published: Nov. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1871
Cross-site scripting (XSS) vulnerability in chcounter 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the login_name parameter to /stats/.... Read more
Affected Products : chcounter- Published: Apr. 13, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1904
Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.... Read more
- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-34888
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.... Read more
Affected Products : thinkstation_p920_firmware thinkagile_hx_enclosure_certified_node_firmware thinkagile_vx3331_firmware thinkagile_hx1021_firmware thinkagile_hx1320_firmware thinkagile_hx1321_firmware thinkagile_hx1520-r_firmware thinkagile_hx1521-r_firmware thinkagile_hx2320-e_firmware thinkagile_hx2321_firmware +186 more products- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4059
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog... Read more
Affected Products : profile_builder- Published: Sep. 04, 2023
- Modified: Mar. 06, 2025