Latest CVE Feed
-
4.3
MEDIUMCVE-2002-2115
Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS) Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to inject arbitrary web script or HTML.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-0565
Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.... Read more
Affected Products : websphere_application_server- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0549
Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers ... Read more
Affected Products : websphere_portal- Published: Jun. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-14628
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.... Read more
- Published: Jan. 17, 2023
- Modified: Jan. 22, 2025
-
4.3
MEDIUMCVE-2011-1176
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which mig... Read more
- Published: Mar. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1077
Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : archiva- Published: Jun. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0876
Unspecified vulnerability in the Enterprise Manager Console component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attac... Read more
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0789
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0785
Unspecified vulnerability in the Oracle Help component in Oracle Database Server 11.1.0.7, 11.2.0.1, 11.2.0.2, 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, and 10.1.0.5; and Oracle Fusion Middleware 11.1.1.2.0, 11.1.1.3.0, and 11.1.1.4.0 allows remote attacker... Read more
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-12123
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed ... Read more
Affected Products : node.js- Published: Nov. 28, 2018
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2013-1012
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.... Read more
Affected Products : safari- Published: Jun. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0653
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."... Read more
- Published: Sep. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1051
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party... Read more
- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0552
Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashb... Read more
Affected Products : im_manager- Published: Oct. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0550
Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token p... Read more
Affected Products : endpoint_protection- Published: Aug. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1087
Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML via the body of an e-mail message.... Read more
- Published: Jul. 15, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1096
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.... Read more
Affected Products : identity_manager_roles_based_provisioning_module- Published: Dec. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1097
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.... Read more
Affected Products : zenworks_configuration_management- Published: Jun. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-48068
Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limited source code exposure when the dev server was running with the App Router ... Read more
Affected Products : next.js- Published: May. 30, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2013-5006
main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the "... Read more
- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025