Latest CVE Feed
-
4.3
MEDIUMCVE-2010-0097
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged... Read more
Affected Products : bind- Published: Jan. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-2630
Unspecified vulnerability in the Technology stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Applet startup.... Read more
Affected Products : e-business_suite- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3192
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."... Read more
Affected Products : internet_explorer- Published: Aug. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-3701
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web ... Read more
- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2536
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Elevation of Pri... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-41437
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.... Read more
Affected Products : manageengine_opmanager- Published: Jun. 09, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2021-24730
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and ... Read more
Affected Products : logo_showcase_with_slick_slider- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-24207
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.... Read more
Affected Products : wp_page_builder- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-1183
The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.... Read more
- Published: Apr. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-24698
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.... Read more
Affected Products : simple_download_monitor- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1627
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."... Read more
Affected Products : internet_explorer- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-24725
The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments... Read more
Affected Products : comment_link_remove_and_other_comment_tools- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3704
The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that t... Read more
Affected Products : libzypp- Published: Oct. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1312
Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) ... Read more
- Published: Apr. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4264
The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.... Read more
Affected Products : ffmpeg- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-1264
Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feature.... Read more
- Published: May. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1236
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and ... Read more
- Published: Apr. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-2163
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : php_script- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-1159
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.... Read more
Affected Products : cups- Published: Jun. 26, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-24733
The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.... Read more
Affected Products : wp_post_page_clone- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024