Latest CVE Feed
-
4.3
MEDIUMCVE-2017-8723
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specia... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-2076
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions ... Read more
Affected Products : xen- Published: Aug. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3321
Multiple cross-site scripting (XSS) vulnerabilities in openforum.asp in OpenForum 1.2 Beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ofdisp and (2) ofmsgid parameters.... Read more
Affected Products : openforum- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-2081
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.... Read more
Affected Products : moodle- Published: May. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-4628
Cross-site scripting (XSS) vulnerability in VCD-db before 0.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when handling comments.... Read more
Affected Products : vcd-db- Published: Sep. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-0790
Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.... Read more
Affected Products : smokeping- Published: Jan. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-3285
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.... Read more
Affected Products : comersus_backoffice_plus- Published: Oct. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2751
Cross-site scripting (XSS) vulnerability in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary web scripts or HTML via the item_list parameter in search.php.... Read more
Affected Products : open_searchable_image_catalogue- Published: Jun. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-3047
Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers to spoof URLs.... Read more
Affected Products : opera_browser- Published: Sep. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-2663
Multiple cross-site scripting (XSS) vulnerabilities in iFlance 1.1 allow remote attackers to inject arbitrary web script or HTML via certain inputs to (1) acc_verify.php or (2) project.php.... Read more
Affected Products : iflance- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-1006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientN... Read more
Affected Products : struts- Published: Feb. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2172
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to spec... Read more
Affected Products : santuario_xml_security_for_java- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2173
wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.... Read more
Affected Products : wordpress- Published: Jun. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1098
Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through ... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2199
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.... Read more
Affected Products : wordpress- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-7764
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.... Read more
Affected Products : u.motion_builder- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-2191
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.... Read more
- Published: Feb. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1107
The analyzeCurrent function in ape/apeproperties.cpp in TagLib 1.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted sampleRate in an ape file, which triggers a divide-by-zero error.... Read more
- Published: Sep. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-2642
** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in Marco M. F. De Santis Php-residence 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via... Read more
Affected Products : php-residence- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2639
Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element.... Read more
Affected Products : phpsimplechoose- Published: May. 30, 2006
- Modified: Apr. 03, 2025