Latest CVE Feed
-
3.5
LOWCVE-2024-52887
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.... Read more
Affected Products :- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-12683
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : smart_maintenance_mode- Published: Mar. 26, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-47700
Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions... Read more
Affected Products : mattermost_server- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2020-28838
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.... Read more
Affected Products : opencart- EPSS Score: %0.10
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-56082
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.... Read more
Affected Products :- Published: Dec. 15, 2024
- Modified: Dec. 16, 2024
-
3.5
LOWCVE-2020-26220
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version... Read more
Affected Products : touchbase.ai- EPSS Score: %0.20
- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-6879
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request... Read more
- EPSS Score: %0.14
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-32007
This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability in web server of Secomea GateManager to potentially leak information to remote servers.... Read more
Affected Products : gatemanager- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
3.5
LOWCVE-2020-14732
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- EPSS Score: %0.18
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-2793
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerab... Read more
Affected Products : flexcube_universal_banking- EPSS Score: %0.26
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-5301
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP ... Read more
Affected Products : simplesamlphp- EPSS Score: %0.14
- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-1010310
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tool... Read more
Affected Products : glpi- EPSS Score: %0.24
- Published: Jul. 12, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2006-6822
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a m... Read more
Affected Products : eclassifieds- EPSS Score: %3.20
- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-0519
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.... Read more
Affected Products : u2u_instant_messenger- EPSS Score: %0.22
- Published: Jan. 26, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-4002
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.25
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6548
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/re... Read more
Affected Products : webhost_manager- EPSS Score: %0.24
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-4360
Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal_e-commerce_module- EPSS Score: %0.29
- Published: Aug. 27, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2005-4855
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certai... Read more
Affected Products : ez_publish- EPSS Score: %0.16
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-4542
Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data stor... Read more
Affected Products : unity- EPSS Score: %0.34
- Published: Oct. 13, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-5026
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-si... Read more
Affected Products : sharepoint_server- EPSS Score: %16.27
- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025