Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 3.5

    LOW
    CVE-2008-6170

    Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.... Read more

    Affected Products : drupal
    • EPSS Score: %0.28
    • Published: Feb. 19, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-3581

    Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or HTML via (1) the DCN Description field in the Accounts Receivables menu item for Add Transaction, (2) the Descripti... Read more

    Affected Products : sql-ledger
    • EPSS Score: %0.20
    • Published: Dec. 23, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2014-5411

    Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : clearscada scada_expert_clearscada
    • EPSS Score: %0.34
    • Published: Sep. 18, 2014
    • Modified: Apr. 12, 2025
  • 3.5

    LOW
    CVE-2009-0481

    Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers... Read more

    Affected Products : bugzilla
    • EPSS Score: %0.23
    • Published: Feb. 09, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2009-0093

    Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Disco... Read more

    • EPSS Score: %51.11
    • Published: Mar. 11, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2012-3865

    Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the p... Read more

    Affected Products : puppet_enterprise puppet puppet
    • EPSS Score: %2.15
    • Published: Aug. 06, 2012
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2011-1503

    The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.... Read more

    Affected Products : windows_7 linux_kernel liferay_portal
    • EPSS Score: %0.66
    • Published: May. 07, 2011
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2013-5001

    Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object... Read more

    Affected Products : phpmyadmin
    • EPSS Score: %0.18
    • Published: Jul. 31, 2013
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2013-3742

    Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name tha... Read more

    Affected Products : phpmyadmin
    • EPSS Score: %0.18
    • Published: Jul. 04, 2013
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2013-3810

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA Transactions.... Read more

    Affected Products : mysql
    • EPSS Score: %0.67
    • Published: Jul. 17, 2013
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2024-22438

    A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820 Network switches. The vulnerability could be remotely exploited to allow execution of malicious code. ... Read more

    Affected Products :
    • Published: Apr. 15, 2024
    • Modified: Nov. 21, 2024
  • 3.5

    LOW
    CVE-2013-4340

    wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.... Read more

    Affected Products : wordpress
    • EPSS Score: %1.22
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 3.5

    LOW
    CVE-2016-0610

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more

    • EPSS Score: %0.63
    • Published: Jan. 21, 2016
    • Modified: Apr. 12, 2025
  • 3.5

    LOW
    CVE-2009-1971

    Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors.... Read more

    Affected Products : database_server
    • EPSS Score: %0.52
    • Published: Oct. 22, 2009
    • Modified: Apr. 09, 2025
  • 3.5

    LOW
    CVE-2020-14791

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to comp... Read more

    • EPSS Score: %0.56
    • Published: Oct. 21, 2020
    • Modified: Nov. 21, 2024
  • 3.5

    LOW
    CVE-2018-2767

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low privi... Read more

    • EPSS Score: %0.38
    • Published: Jul. 18, 2018
    • Modified: Nov. 21, 2024
  • 3.5

    LOW
    CVE-2020-24588

    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MS... Read more

    • EPSS Score: %0.34
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 3.5

    LOW
    CVE-2016-1500

    ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the file... Read more

    Affected Products : owncloud owncloud_server
    • EPSS Score: %0.29
    • Published: Jan. 08, 2016
    • Modified: Apr. 12, 2025
  • 3.5

    LOW
    CVE-2013-3004

    Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors.... Read more

    • EPSS Score: %0.14
    • Published: Jul. 01, 2014
    • Modified: Apr. 12, 2025
  • 3.5

    LOW
    CVE-2013-1840

    The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for... Read more

    Affected Products : glance swift glance folsom essex s3_store
    • EPSS Score: %0.34
    • Published: Mar. 22, 2013
    • Modified: Apr. 11, 2025
Showing 20 of 291756 Results