CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
ZEROF Web Server 2.0 allows /admin.back XSS.
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
