Latest CVE Feed
-
4.3
MEDIUMCVE-2015-5066
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q paramete... Read more
Affected Products : genixcms- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-0390
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.... Read more
Affected Products : diagnostics_agent- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5529
Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to dashboard/settings/categories/, (2) title or (3) rel parameter to dashboar... Read more
Affected Products : articlefr- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7200
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via the tx_dmmjobcontrol_pi1[search][key... Read more
Affected Products : dmmjobcontrol- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-19148
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for ... Read more
Affected Products : caddy- Published: Nov. 10, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4871
Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject arbitrary web script or HTML via the wlWpaPsk parameter.... Read more
- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1224
Incomplete blacklist vulnerability in the user registration feature in rexx Recruitment R6.1 and R7 without "fixes from 2014-01-15" allows remote attackers to conduct cross-site scripting (XSS) attacks via the oninput event handler in the fname parameter ... Read more
Affected Products : recruitment- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-2251
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.... Read more
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6296
Cross-site scripting (XSS) vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wec_map- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-16909
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects (with authentication as a Jira user, but without authorization for specific projects) via the plu... Read more
Affected Products : in-app_\&_desktop_notifications- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.... Read more
Affected Products : yith_woocommerce_wishlist yith_woocommerce_compare yith_woocommerce_quick_view yith_woocommerce_zoom_magnifier yith_woocommerce_ajax_search yith_woocommerce_badge_management yith_woocommerce_brands_add-on yith_woocommerce_request_a_quote yith_woocommerce_social_login yith_woocommerce_order_tracking +28 more products- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-18365
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.... Read more
Affected Products : teamcity- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-13919
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited by a... Read more
Affected Products : sinema_remote_connect_server- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-14725
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail usage value of a victim account via an attacker account.... Read more
Affected Products : webpanel- Published: Sep. 11, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-0356
Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.... Read more
Affected Products : netweaver_process_integration- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-14723
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a victim's e-mail account via an attacker account.... Read more
Affected Products : webpanel- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-3848
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar e... Read more
Affected Products : moodle- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-19620
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.... Read more
Affected Products : showdoc- Published: Nov. 28, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-20898
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3991
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu, (5) dol_hi... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 11, 2014
- Modified: Apr. 12, 2025