Latest CVE Feed
-
3.5
LOWCVE-2013-5698
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML vi... Read more
- EPSS Score: %0.16
- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0858
Unspecified vulnerability in the E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.38
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4753
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field in an inbox action to messaging/messagebox.php, (2) the "First name" field... Read more
Affected Products : claroline- EPSS Score: %0.16
- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-32159
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.... Read more
Affected Products : infogami- EPSS Score: %0.32
- Published: Jun. 22, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2025-49810
Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts... Read more
Affected Products : mattermost_server- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2014-4787
Cross-site scripting (XSS) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to inject arbitrary web script or HTML via un... Read more
Affected Products : initiate_master_data_service- EPSS Score: %0.18
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2025-55523
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2008-6299
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2... Read more
Affected Products : joomla- EPSS Score: %0.01
- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-4836
Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web s... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.19
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2005-4191
Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description,... Read more
Affected Products : nag_task_list_manager_h3- EPSS Score: %0.37
- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2012-1628
Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3544
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Sky... Read more
Affected Products : moodle- EPSS Score: %0.96
- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-0351
A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an unknown part. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The complexity of an attack ... Read more
Affected Products : engineers_online_portal- EPSS Score: %0.05
- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-45715
The console may experience a service interruption when processing file names with invalid characters. ... Read more
Affected Products : bigfix_platform- Published: Mar. 28, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-20677
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (... Read more
- EPSS Score: %0.30
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-31684
Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a deprecated API.... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2017-3487
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploi... Read more
Affected Products : flexcube_investor_servicing- EPSS Score: %0.25
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-3490
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vu... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- EPSS Score: %0.25
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-4874
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.... Read more
Affected Products : office- EPSS Score: %0.23
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2021-25075
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and chang... Read more
Affected Products : duplicate_page_or_post- EPSS Score: %9.88
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024