Latest CVE Feed
-
4.3
MEDIUMCVE-2013-4569
The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3, when "Group changes by page in recent changes and watchlist" is enabled, allows remote attackers to obtain sensitive information (revision-deleted IPs)... Read more
Affected Products : mediawiki- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-7196
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the ... Read more
Affected Products : tomcat- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-30538
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.... Read more
- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-3058
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with netw... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation mysql mariadb oncommand_insight oncommand_workflow_automation snapcenter +2 more products- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0035
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to o... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0028
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virCo... Read more
Affected Products : libvirt- Published: Jan. 24, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4264
The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.... Read more
Affected Products : ffmpeg- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3758
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduc... Read more
- Published: Sep. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5523
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.... Read more
- Published: Aug. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3704
The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that t... Read more
Affected Products : libzypp- Published: Oct. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-4312
The Soccer Engine – Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation when saving match and team settings. This mak... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1159
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.... Read more
Affected Products : cups- Published: Jun. 26, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0623
Cross-site scripting (XSS) vulnerability in the Self-Service Console in EMC RSA Authentication Manager 7.1 before SP4 P32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" issue.... Read more
- Published: Mar. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2931
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an application/xml MIME type for a nested SVG... Read more
Affected Products : mediawiki- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3799
The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id ... Read more
Affected Products : php- Published: Jul. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3192
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."... Read more
Affected Products : internet_explorer- Published: Aug. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-4189
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search, (2) com_content, and (3) mod_login components. NOTE: s... Read more
- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1480
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a down... Read more
- Published: Feb. 06, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-2536
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Elevation of Pri... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-25110
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.... Read more
Affected Products : futurio_extra- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024