Latest CVE Feed
-
3.5
LOWCVE-2024-33000
SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-3157
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, 6.0.1, 6.2.0, and 12 allows remote authenticated users to affect integrity, related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.19
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-30107
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. ... Read more
Affected Products : connections- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-3454
An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed t... Read more
Affected Products : matter- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-6148
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sen... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.17
- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8075
Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : tribune- EPSS Score: %0.15
- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to injec... Read more
- EPSS Score: %2.02
- Published: Dec. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6726
Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.17
- Published: May. 07, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4246
Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.... Read more
Affected Products : hyperion- EPSS Score: %0.58
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-0991
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_f... Read more
- EPSS Score: %70.71
- Published: Feb. 07, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3870
Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) name or (2) description parameter.... Read more
Affected Products : openconstructor- EPSS Score: %0.22
- Published: Dec. 28, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-6163
Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware- EPSS Score: %0.19
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-2955
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, related to a stored XSS i... Read more
Affected Products : infosphere_optim_data_growth_for_oracle_e-business_suite- EPSS Score: %0.17
- Published: May. 27, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-4337
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.... Read more
Affected Products : xcloner- EPSS Score: %0.18
- Published: Jun. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3923
The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session in... Read more
Affected Products : ios- EPSS Score: %0.38
- Published: Sep. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3192
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity, related to Rich Text Editor (RTE).... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.15
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5939
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.19
- Published: Mar. 06, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3316
Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Requ... Read more
- EPSS Score: %0.19
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2008-2849
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : trailscout_module- EPSS Score: %0.15
- Published: Jun. 25, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-6913
Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.23
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025