Latest CVE Feed
-
3.5
LOWCVE-2010-0460
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) i... Read more
- EPSS Score: %0.34
- Published: Jan. 28, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3503
The Profile Importer feature in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an enti... Read more
Affected Products : groundwork_monitor- EPSS Score: %0.39
- Published: May. 08, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2021-26988
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Vi... Read more
- EPSS Score: %0.14
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-6310
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : marketing_platform- EPSS Score: %0.17
- Published: Jun. 28, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-1810
FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.... Read more
- EPSS Score: %0.12
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5811
Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authentic... Read more
Affected Products : industry_applications- EPSS Score: %0.14
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2535
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.... Read more
Affected Products : joomla\!- EPSS Score: %0.02
- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4790
Open-Xchange AppSuite before 7.0.2 rev14, 7.2.0 before rev11, 7.2.1 before rev10, and 7.2.2 before rev9 relies on user-supplied data to predict the IMAP server hostname for an external domain name, which allows remote authenticated users to discover e-mai... Read more
Affected Products : open-xchange_appsuite- EPSS Score: %0.28
- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0858
Unspecified vulnerability in the E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.38
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5698
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML vi... Read more
- EPSS Score: %0.16
- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-30950
A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.... Read more
Affected Products : fudforum- Published: Apr. 17, 2024
- Modified: Jun. 10, 2025
-
3.5
LOWCVE-2021-20677
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (... Read more
- EPSS Score: %0.30
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-2159
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more
- EPSS Score: %0.19
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-4132
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.28
- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2289
Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when cre... Read more
Affected Products : serendipity- EPSS Score: %0.34
- Published: Mar. 23, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-1461
Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Page Title field.... Read more
Affected Products : razorcms- EPSS Score: %0.20
- Published: Apr. 28, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-4532
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform creation privileges, to inject arbitrary web script or HTML via a field label.... Read more
- EPSS Score: %0.34
- Published: Dec. 31, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-2197
Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.... Read more
Affected Products : entity_api- EPSS Score: %0.21
- Published: Mar. 03, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2017-18436
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).... Read more
Affected Products : cpanel- EPSS Score: %0.06
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-1982
Cross-site scripting (XSS) vulnerability in my_admin/admin1_list_pages.php in SocialCMS 1.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the TR_title parameter in an edit action.... Read more
Affected Products : socialcms- EPSS Score: %0.16
- Published: Apr. 05, 2012
- Modified: Apr. 11, 2025