Latest CVE Feed
-
3.5
LOWCVE-2010-1810
FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.... Read more
- EPSS Score: %0.12
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5502
Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : plone- EPSS Score: %0.15
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-47799
Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain information o... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
3.5
LOWCVE-2021-36181
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data... Read more
Affected Products : fortiportal- EPSS Score: %0.37
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-11140
The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter... Read more
Affected Products : real_wp_shop_lite_ajax_ecommerce_shopping_cart- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2022-24744
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.... Read more
Affected Products : shopware- EPSS Score: %0.15
- Published: Mar. 09, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2008-6299
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2... Read more
Affected Products : joomla- EPSS Score: %0.01
- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-4848
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (... Read more
Affected Products : lotus_foundations_start- EPSS Score: %0.17
- Published: Dec. 19, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1628
Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-12273
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is di... Read more
Affected Products : calculated_fields_form- Published: Apr. 29, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2023-52371
Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Feb. 18, 2024
- Modified: Dec. 04, 2024
-
3.5
LOWCVE-2014-3096
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.17
- Published: Jan. 10, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0103
Multiple cross-site scripting (XSS) vulnerabilities in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allow remote authenticated users to inject arbitrary web script or HTML v... Read more
Affected Products : business_process_manager- EPSS Score: %0.18
- Published: Mar. 24, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-1653
Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to "views pages."... Read more
- EPSS Score: %0.34
- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2021
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the cli... Read more
Affected Products : vbulletin- EPSS Score: %1.19
- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-2299
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.49
- Published: Aug. 22, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0297
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) site_name or (2) site_url parameter to apps/external/ajax/set... Read more
- EPSS Score: %0.18
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-0537
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of shared links by leveraging meeting-attendance privileges.... Read more
- EPSS Score: %0.15
- Published: Nov. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2008-3095
Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unsp... Read more
- EPSS Score: %0.15
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-1481
Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.... Read more
Affected Products : pmwiki- EPSS Score: %0.20
- Published: May. 12, 2010
- Modified: Apr. 11, 2025