Latest CVE Feed
-
3.5
LOWCVE-2019-1010310
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tool... Read more
Affected Products : glpi- EPSS Score: %0.24
- Published: Jul. 12, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-4523
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.p... Read more
Affected Products : ripe_website_manager- EPSS Score: %0.43
- Published: Aug. 25, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-6215
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web... Read more
Affected Products : websphere_portal- EPSS Score: %0.19
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6180
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the HTTP User-Agent h... Read more
Affected Products : websphere_service_registry_and_repository- EPSS Score: %0.16
- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7827
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authe... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.32
- Published: Feb. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3594
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host a... Read more
- EPSS Score: %0.60
- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8986
Cross-site scripting (XSS) vulnerability in the selection list in the filters in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via a crafted conf... Read more
Affected Products : mantisbt- EPSS Score: %0.53
- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-4427
Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote authenticated users to modify data on a server, related to encoding of cert... Read more
Affected Products : cache_database- EPSS Score: %0.22
- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-5571
OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for th... Read more
- EPSS Score: %0.31
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-4413
Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote authenticated users to inject arbitrary PHP code into an unspecified file via a new_entry value in the do parameter.... Read more
Affected Products : deskpro- EPSS Score: %0.19
- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-3102
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- EPSS Score: %0.16
- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-1511
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more
- EPSS Score: %0.57
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13615
The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr... Read more
Affected Products : social_snap- Published: Mar. 11, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2015-4739
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors related to Help screens.... Read more
Affected Products : e-business_suite- EPSS Score: %0.15
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-2282
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50.20 and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors.... Read more
- EPSS Score: %0.29
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-1491
The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to th... Read more
- EPSS Score: %0.39
- Published: Apr. 08, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-2243
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7.3, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect integrity, related to SYSDBA.... Read more
Affected Products : database_server- EPSS Score: %0.18
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-0086
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012... Read more
Affected Products : fusion_middleware- EPSS Score: %0.14
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-1405
Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.php.... Read more
Affected Products : mahara- EPSS Score: %0.29
- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-2274
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-228... Read more
- EPSS Score: %0.29
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025