Latest CVE Feed
-
4.3
MEDIUMCVE-2007-2896
Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2004-2484
Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.... Read more
Affected Products : phpgiftreg- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-3613
Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.... Read more
Affected Products : internet_graphics_server- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-2397
Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin parameter.... Read more
Affected Products : phpbook- Published: Jul. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-5531
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthe... Read more
Affected Products : thumbnail_slider_with_lightbox- Published: Oct. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-0623
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2638
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchR... Read more
Affected Products : phpfreenews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-1716
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : xymon- Published: Apr. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-31544
Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Swiss Toolkit For WP: from n/a through 1.3.0.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-4432
Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.... Read more
- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4481
Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : redmine- Published: Oct. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4532
Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.... Read more
Affected Products : website_directory- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4520
Cross-site scripting (XSS) vulnerability in bulk_update.pl in AutoNessus before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the remark parameter.... Read more
Affected Products : autonessus- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4663
Cross-site scripting (XSS) vulnerability in analysis.cgi 1.44, as used in K's CGI Access Log Kaiseki (1) jcode.pl and (2) Jcode.pm, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : ks_cgi_access_log- Published: Oct. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-2710
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is... Read more
Affected Products : joomla\!- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2761
Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web site, related to GetWidget methods.... Read more
Affected Products : chrome- Published: Jul. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6407
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or ... Read more
Affected Products : tivoli_provisioning_manager_express- Published: Dec. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6699
Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) Fina... Read more
Affected Products : ygp_piceditor_activex_control- Published: Feb. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0093
Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.... Read more
Affected Products : eticket- Published: Jan. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0182
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.... Read more
Affected Products : liferay_enterprise_portal- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025