Latest CVE Feed
-
3.5
LOWCVE-2012-3224
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.1.0, 5.2.0, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality, related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.22
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-7246
The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in... Read more
Affected Products : openam- EPSS Score: %0.48
- Published: Nov. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6237
Cross-site scripting (XSS) vulnerability in the News Pack extension 0.1.0 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : news_pack- EPSS Score: %0.21
- Published: Sep. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6232
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.... Read more
Affected Products : spagobi- EPSS Score: %1.02
- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-5442
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users who attempt uploads, which allows remote authenticated users to upload unspecified files via unknown vectors.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.13
- Published: Oct. 14, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-3147
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.... Read more
Affected Products : splunk- EPSS Score: %0.18
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4365
Cross-site scripting (XSS) vulnerability in the Taxonomy Accordion module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.... Read more
Affected Products : taxonomy_accordion- EPSS Score: %0.16
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-5446
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from t... Read more
- EPSS Score: %0.38
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-8734
The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors.... Read more
Affected Products : organic_groups_menu- EPSS Score: %0.19
- Published: Nov. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-4523
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.p... Read more
Affected Products : ripe_website_manager- EPSS Score: %0.43
- Published: Aug. 25, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-8330
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.... Read more
Affected Products : espocrm- EPSS Score: %0.16
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0473
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core.... Read more
- EPSS Score: %0.15
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8076
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright info... Read more
Affected Products : professional_theme- EPSS Score: %0.20
- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-3262
Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.... Read more
Affected Products : tivoli_identity_manager- EPSS Score: %0.19
- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-3443
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbitrary web script or HTML via a password entry, which is not properly handle... Read more
Affected Products : secret_server- EPSS Score: %1.14
- Published: Jul. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-4309
IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-... Read more
- EPSS Score: %0.18
- Published: Aug. 13, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2016-5618
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.2.0.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Cod... Read more
Affected Products : data_integrator- EPSS Score: %0.18
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2025-37108
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2016-6001
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.... Read more
Affected Products : forms_experience_builder- EPSS Score: %0.14
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2021-20761
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.... Read more
Affected Products : garoon- EPSS Score: %0.15
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024