Latest CVE Feed
-
4.3
MEDIUMCVE-2007-3756
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the pa... Read more
- Published: Sep. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6086
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3742
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike ch... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3553
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP0... Read more
- Published: Jul. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-39412
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass securi... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2015-6052
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR... Read more
- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-39416
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass securi... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
4.3
MEDIUMCVE-2007-2581
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "e... Read more
- Published: May. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6046
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-1894
Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.... Read more
Affected Products : wordpress- Published: Apr. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2911
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.... Read more
Affected Products : contendio- Published: Jun. 30, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2718
Cross-site scripting (XSS) vulnerability in fe_adminlib.inc in TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, as used in extensions such as (1) direct_mail_subscription, (2) feuser_admin, and (3) kb_md5fepw, allows remote attackers ... Read more
Affected Products : typo3- Published: Jun. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0810
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)... Read more
- Published: Jan. 24, 2024
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2024-0372
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_form_fields' function in all versions up to, and including, 3.2.2.... Read more
Affected Products : views_for_wpforms- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0748
A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.... Read more
Affected Products : firefox- Published: Jan. 23, 2024
- Modified: Jun. 11, 2025
-
4.3
MEDIUMCVE-2024-0371
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'create_view' function in all versions up to, and including, 3.2.... Read more
Affected Products : views_for_wpforms- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3773
Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka new... Read more
Affected Products : vbulletin- Published: Aug. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0507
Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.... Read more
Affected Products : easy_cms- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-4047
IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.... Read more
Affected Products : jazz_reporting_service- Published: Apr. 29, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2526
Cross-site scripting (XSS) vulnerability in the WT Gallery (aka wt_gallery) extension 2.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wt_gallery- Published: Jun. 03, 2008
- Modified: Apr. 09, 2025