Latest CVE Feed
-
3.5
LOWCVE-2013-6301
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated ... Read more
Affected Products : algo_one- EPSS Score: %0.17
- Published: Mar. 05, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4356
Cross-site scripting (XSS) vulnerability in the view-based webform results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a webform.... Read more
Affected Products : webform- EPSS Score: %0.18
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4586
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permissio... Read more
- EPSS Score: %0.16
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-4367
Cross-site scripting (XSS) vulnerability in the Simple Subscription module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer blocks" permission to inject arbitrary web script or HTML via vectors re... Read more
Affected Products : simple_subscription- EPSS Score: %0.23
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4369
Cross-site scripting (XSS) vulnerability in the Trick Question module before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Trick Question" permission to inject arbitrary web script or HTML via unspeci... Read more
Affected Products : trick_question- EPSS Score: %0.23
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7264
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Management feature in the admin component in Chyrp before 2.5.1 allow remote authenticated users to inject arbitrary web script or HTML via th... Read more
Affected Products : chyrp- EPSS Score: %0.18
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4373
Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.... Read more
Affected Products : og_tabs- EPSS Score: %0.15
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4376
Cross-site scripting (XSS) vulnerability in the Profile2 Privacy module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Profile2 Privacy Levels" permission to inject arbitrary web script or HTML via unspecified vec... Read more
Affected Products : profile2_privacy- EPSS Score: %0.23
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4359
Multiple cross-site scripting (XSS) vulnerabilities in the Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8, and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with permission to create or edit taxonomy terms or nodes t... Read more
Affected Products : registration_codes- EPSS Score: %0.34
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-9098
Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoads... Read more
Affected Products : contus_video_gallery- EPSS Score: %0.23
- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4381
Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "Administer own invoices" permission to inject arbitrary web script or HTML via unspecif... Read more
Affected Products : invoice- EPSS Score: %0.23
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-0307
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.... Read more
- EPSS Score: %0.28
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-5026
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-si... Read more
Affected Products : sharepoint_server- EPSS Score: %16.27
- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-1851
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the user's account via unspecified vectors... Read more
- EPSS Score: %0.17
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-9346
Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonom... Read more
Affected Products : hierarchical_select- EPSS Score: %0.15
- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-2802
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.2 allows remote authenticated users to inject arbitrary web script or HTML via an HTML document with a .gif filename extension, related to inline attachments.... Read more
Affected Products : mantisbt- EPSS Score: %0.23
- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-0551
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Docum... Read more
- EPSS Score: %0.16
- Published: Jul. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3179
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Tree Manager.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.19
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-3961
The web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allows remote authenticated users to cause a denial of service (memory corruption and reboot) via a crafted URL.... Read more
- EPSS Score: %0.92
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0144
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vul... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.17
- Published: Oct. 03, 2015
- Modified: Apr. 12, 2025