Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 3.5

    LOW
    CVE-2006-6775

    acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.... Read more

    Affected Products : acftp
    • EPSS Score: %4.22
    • Published: Dec. 27, 2006
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2008-4152

    Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more

    Affected Products : talk
    • EPSS Score: %0.23
    • Published: Sep. 24, 2008
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2008-3903

    Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, whe... Read more

    Affected Products : p_b_x pbx
    • EPSS Score: %0.67
    • Published: Sep. 04, 2008
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3653

    Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permission, to inject arbitrary web script or HTML via unspecif... Read more

    Affected Products : drupal xml_sitemap
    • EPSS Score: %0.20
    • Published: Oct. 09, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2008-7286

    IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.... Read more

    Affected Products : lotus_quickr lotus_domino
    • EPSS Score: %0.34
    • Published: Mar. 22, 2011
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2009-2131

    Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a pictu... Read more

    Affected Products : 4images
    • EPSS Score: %1.02
    • Published: Jun. 19, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-4105

    TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command without sending file data in between these two commands.... Read more

    Affected Products : typsoft_ftp_server
    • EPSS Score: %3.16
    • Published: Nov. 29, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3262

    Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.... Read more

    Affected Products : tivoli_identity_manager
    • EPSS Score: %0.19
    • Published: Sep. 18, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-2076

    Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name p... Read more

    Affected Products : drupal views
    • EPSS Score: %0.18
    • Published: Jun. 16, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-1844

    Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6... Read more

    Affected Products : drupal
    • EPSS Score: %0.14
    • Published: Jun. 01, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2005-4191

    Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description,... Read more

    Affected Products : nag_task_list_manager_h3
    • EPSS Score: %0.37
    • Published: Dec. 13, 2005
    • Modified: Apr. 03, 2025
  • 3.5

    LOW
    CVE-2009-3157

    Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web script or HTML via the title of a content type.... Read more

    Affected Products : drupal calendar
    • EPSS Score: %0.34
    • Published: Sep. 10, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2008-5999

    Cross-site scripting (XSS) vulnerability in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allows remote authenticated users, with create and edit permissions for posts, to inject arbitrary web script or HTML via unspecified vectors involving the... Read more

    Affected Products : drupal ajax_checklist
    • EPSS Score: %0.16
    • Published: Jan. 28, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3487

    Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec... Read more

    Affected Products : junos junos
    • EPSS Score: %0.24
    • Published: Sep. 30, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3648

    Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content ... Read more

    Affected Products : drupal service_links
    • EPSS Score: %0.14
    • Published: Oct. 09, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3782

    Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.... Read more

    Affected Products : drupal userpoints
    • EPSS Score: %0.28
    • Published: Oct. 26, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2008-7231

    Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) o... Read more

    Affected Products : document_and_records_management
    • EPSS Score: %0.20
    • Published: Sep. 14, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3652

    Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbi... Read more

    Affected Products : drupal organic_groups
    • EPSS Score: %0.27
    • Published: Oct. 09, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2008-7284

    IBM Lotus Quickr 8.1 before 8100.003 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by clicking a download link, aka SPR QCAO7E6AM8.... Read more

    Affected Products : lotus_quickr lotus_domino
    • EPSS Score: %0.34
    • Published: Mar. 22, 2011
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2009-2074

    Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via vocabulary names.... Read more

    Affected Products : drupal nodequeue
    • EPSS Score: %0.25
    • Published: Jun. 16, 2009
    • Modified: Apr. 09, 2025
Showing 20 of 292485 Results