Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2133
Cross-site scripting (XSS) vulnerability in the Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter in a new entry, as demonstrated by a CSS property in the STYLE attribute of a DIV... Read more
Affected Products : nukeet- Published: May. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2163
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."... Read more
- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2166
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.... Read more
Affected Products : java_system_web_server- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2196
Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.... Read more
Affected Products : lifetype- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2593
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2594.... Read more
Affected Products : application_server- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2131
Cross-site scripting (XSS) vulnerability in mvnForum 1.1 GA allows remote authenticated users to inject arbitrary web script or HTML via the topic field, which is later displayed by user/viewthread.jsp through use of the "quick reply button."... Read more
Affected Products : mvnforum- Published: May. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0195
Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier,... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-57759
Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in... Read more
Affected Products : contao- Published: Aug. 28, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-2200
Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 param... Read more
Affected Products : maian_weblog- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-6870
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.... Read more
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6897
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it po... Read more
Affected Products : ean_for_woocommerce- Published: Apr. 18, 2024
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2008-2333
Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : barracuda_spam_firewall- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1021
Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable).... Read more
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2162
Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page.... Read more
Affected Products : e-mail_security- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0210
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.... Read more
Affected Products : trackpoint_nx- Published: Jan. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2165
Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : building_broadband_service_manager- Published: May. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-10903
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-13580
The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack... Read more
- Published: Mar. 11, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-2302
Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain p... Read more
- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-6868
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.*... Read more
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024