Latest CVE Feed
-
3.5
LOWCVE-2011-4560
Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition.... Read more
- EPSS Score: %0.23
- Published: Nov. 28, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2021-33031
In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without access to user management in order to, after successful exploitation, gain access to a victim's account. A user without the user-manageme... Read more
Affected Products : labcup- EPSS Score: %0.14
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2010-3581
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- EPSS Score: %5.34
- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-0279
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users... Read more
Affected Products : anycomment- EPSS Score: %0.13
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-26476
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.... Read more
- Published: Feb. 28, 2024
- Modified: May. 13, 2025
-
3.5
LOWCVE-2014-2067
Cross-site scripting (XSS) vulnerability in java/hudson/model/Cause.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to inject arbitrary web script or HTML via a "remote cause note."... Read more
Affected Products : jenkins- EPSS Score: %0.09
- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3476
Multiple cross-site scripting (XSS) vulnerabilities in (1) application/views/admin/layout.php and (2) themes/default/views/header.php in the Ushahidi Platform before 2.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors r... Read more
Affected Products : ushahidi_platform- EPSS Score: %0.16
- Published: Aug. 12, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-10515
In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor... Read more
Affected Products : seo_plugin_by_squirrly_seo- Published: Nov. 20, 2024
- Modified: Mar. 31, 2025
-
3.5
LOWCVE-2014-3840
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2) title of a source in a Staging folde... Read more
Affected Products : mayan_edms- EPSS Score: %1.25
- Published: May. 27, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-0533
Cross-site scripting (XSS) vulnerability in the Sametime Links server in IBM Sametime 8.0.2 through 8.5.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.14
- Published: Apr. 28, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-8379
Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to field titles to the (1) Webform ... Read more
Affected Products : marketo_ma- EPSS Score: %0.15
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-24236
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.... Read more
Affected Products : aria- EPSS Score: %0.25
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-8349
Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the _20_body parameter in the comment field in an uploaded file.... Read more
Affected Products : liferay_portal- EPSS Score: %0.25
- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3995
Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights 1.1 through 2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : infosphere_biginsights- EPSS Score: %0.21
- Published: Aug. 06, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-25899
A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.... Read more
- Published: Feb. 13, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Denial of Service
-
3.5
LOWCVE-2014-5420
CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded application password, which makes it easier for remote authenticated users to obtain application-file access via unspecified vectors.... Read more
Affected Products : pyxis_supplystation- EPSS Score: %0.21
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3924
The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP ove... Read more
Affected Products : ios- EPSS Score: %0.38
- Published: Sep. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4587
McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1, when one-time provisioning (OTP) mode is enabled, have an improper dependency on DNS SRV records, which makes it easier for remote attackers to discover user passwords by sp... Read more
- EPSS Score: %0.18
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2021-27913
The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature being one pseudorandomness, an attacker can take advantage of the cryptographically insecure nature of this function to enumerate session ... Read more
Affected Products : mautic- EPSS Score: %0.09
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-0385
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensi... Read more
Affected Products : websphere_application_server- EPSS Score: %0.30
- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025