Latest CVE Feed
-
4.3
MEDIUMCVE-2007-0890
Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.... Read more
Affected Products : webhost_manager- Published: Feb. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-6654
The sendmsg function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029, when run on a 64-bit architecture, allows attackers to cause a denial of service (kernel panic) via an invalid msg_controllen par... Read more
Affected Products : netbsd- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1234
Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (... Read more
Affected Products : sitex- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-49790
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.... Read more
- Published: Dec. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-46254
capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and ... Read more
- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-1049
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the... Read more
- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0649
Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the sr... Read more
- Published: Feb. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0628
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. ... Read more
Affected Products : java_system_access_manager- Published: Jan. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0583
Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Defau... Read more
Affected Products : http_commander- Published: Jan. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-1099
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-0768
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an... Read more
Affected Products : messenger- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-4221
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*... Read more
- Published: Dec. 22, 2022
- Modified: Apr. 16, 2025
-
4.3
MEDIUMCVE-2007-1239
Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.... Read more
Affected Products : excel- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0694
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.... Read more
Affected Products : dgnews- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-49877
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user to obtain sensitive information, caused by improper filtering of URLs. By submitting a specially crafted HTTP GET request, an attacker ... Read more
- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-7189
Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the Statistics Log Viewer.... Read more
Affected Products : webapp- Published: Apr. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0595
Cross-site scripting (XSS) vulnerability in search in High 5 Review Site allows remote attackers to inject arbitrary web script or HTML via the q parameter (aka the search box).... Read more
Affected Products : high5_review_script- Published: Jan. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5486
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.... Read more
- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0451
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."... Read more
Affected Products : spamassassin- Published: Feb. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-40730
Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free that allow a remote attacker to disclose sensitive information on affected i... Read more
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024