Latest CVE Feed
-
4.3
MEDIUMCVE-2003-1519
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.... Read more
Affected Products : clustering_engine- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1578
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS r... Read more
Affected Products : one_web_server- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-1192
Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-1225
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.... Read more
Affected Products : turnkey_ebook_store- Published: Apr. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-19668
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.... Read more
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-4320
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.... Read more
Affected Products : bitbucket- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-22012
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with net... Read more
Affected Products : business_intelligence- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-31448
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malici... Read more
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-11282
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users ... Read more
- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1180
WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.... Read more
Affected Products : webapp- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-1880
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a di... Read more
Affected Products : activemq- Published: Feb. 05, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5205
Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links parameter.... Read more
Affected Products : rapidleech- Published: Oct. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1342
Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form.... Read more
- Published: Mar. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1854
Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message. NOTE: the... Read more
Affected Products : pay_per_watch_\&_bid_auktions_system- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1012
Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the article parameter.... Read more
Affected Products : deskpro- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1433
Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.... Read more
Affected Products : grayscale_blog- Published: Mar. 13, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1506
Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.... Read more
Affected Products : application_server_portal- Published: Mar. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-12973
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.... Read more
Affected Products : nimbus_jose\+jwt- Published: Aug. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-0362
Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when dynamic navigation is configured, allows remote attackers to inject arbitrary web script or HTML via input included in a... Read more
Affected Products : search_appliance_software- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-4580
Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.... Read more
Affected Products : communique- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025