Latest CVE Feed
-
4.3
MEDIUMCVE-2014-8301
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header.... Read more
Affected Products : splunk- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5596
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-7284
Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Dec. 20, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0085
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2 and 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-20635
PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.... Read more
Affected Products : advance_b2b_script- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2532
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability."... Read more
Affected Products : lync_server- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2003-0479
Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.... Read more
Affected Products : affordable_web_space_design_webbbs- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-5460
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8021
Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine 3.1(.05183) and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving an applet-pa... Read more
- Published: Feb. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-55052
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2012-0145
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a UR... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0156
DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant me... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-7991
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core dev... Read more
Affected Products : unified_communications_manager- Published: Nov. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1459
Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.... Read more
Affected Products : fortiauthenticator- Published: Feb. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6318
The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthor... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Published: Nov. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-20155
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.... Read more
Affected Products : wp_maintenance_mode- Published: Dec. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-7983
Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : joomla\!- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-7657
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows attackers to obtain sensitive information from kernel m... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-1566
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dotnetnuke- Published: Feb. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2645
HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors.... Read more
Affected Products : systems_insight_manager- Published: Oct. 05, 2014
- Modified: Apr. 12, 2025