Latest CVE Feed
-
3.5
LOWCVE-2009-0817
Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML... Read more
- EPSS Score: %0.35
- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-4246
Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.... Read more
Affected Products : hyperion- EPSS Score: %0.58
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-24236
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.... Read more
Affected Products : aria- EPSS Score: %0.25
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2017-9139
There is a stack-based buffer overflow on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). Crafted POST requests to an unspecified URL result in DoS, interrupting the HTTP service (used to login to the web UI of a router) for 1 to 2 seco... Read more
- EPSS Score: %0.11
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2012-3924
The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP ove... Read more
Affected Products : ios- EPSS Score: %0.38
- Published: Sep. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-5313
Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0513
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged acc... Read more
- EPSS Score: %0.18
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-4760
Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.... Read more
Affected Products : otrs- EPSS Score: %0.18
- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-9505
Cross-site scripting (XSS) vulnerability in the School Administration module 7.x-1.x before 7.x-1.8 for Drupal allows remote authenticated users with permission to create or edit a class node to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : school_administration- EPSS Score: %0.23
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0967
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows... Read more
- EPSS Score: %0.17
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-1556
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows remote authenticated users to affect integrity via vectors related to OTH.... Read more
Affected Products : financial_services_software- EPSS Score: %0.15
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0468
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-... Read more
- EPSS Score: %0.17
- Published: Jul. 03, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-2998
frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code.... Read more
- EPSS Score: %0.18
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3880
The App Container feature in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to bypass intended access restrictions and obtain sensitive information from a different container via a Trojan horse ... Read more
- EPSS Score: %21.41
- Published: Oct. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2985
Cross-site scripting (XSS) vulnerability in InsertDocument.aspx in CuteSoft Cute Editor 6.4 allows remote authenticated users to inject arbitrary web script or HTML via the _UploadID parameter.... Read more
Affected Products : cute_editor- EPSS Score: %0.21
- Published: Aug. 21, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-3269
Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in a GET request or (2) the Title field of a visitor comment, and (3) allow remote authent... Read more
Affected Products : papoo_cms_light- EPSS Score: %0.58
- Published: Jun. 19, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2020-25688
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacke... Read more
Affected Products : advanced_cluster_management_for_kubernetes- EPSS Score: %0.03
- Published: Nov. 23, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2009-2856
Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-dat... Read more
- EPSS Score: %0.20
- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2020-6317
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sensitive is of limited utility and ca... Read more
Affected Products : adaptive_server_enterprise- EPSS Score: %0.07
- Published: Nov. 30, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-3033
Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via... Read more
Affected Products : emptoris_sourcing_portfolio- EPSS Score: %0.19
- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025