Latest CVE Feed
-
3.5
LOWCVE-2013-2969
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters... Read more
Affected Products : sterling_control_center- EPSS Score: %0.17
- Published: Jun. 19, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-3921
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.... Read more
Affected Products : coppermine_photo_gallery- EPSS Score: %0.18
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0840
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rational_focal_point- EPSS Score: %0.25
- Published: Feb. 26, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-2827
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.22
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6091
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management (SPM) 6.0.4 before 6.0.4.5 iFix7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.17
- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-1627
Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.... Read more
- EPSS Score: %0.32
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-8077
Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors relat... Read more
Affected Products : newsflash- EPSS Score: %0.34
- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2025-37108
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2021-39220
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images... Read more
- EPSS Score: %0.26
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-29066
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.... Read more
- EPSS Score: %0.04
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-18463
Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.... Read more
Affected Products : aikcms- EPSS Score: %0.10
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-25014
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Store... Read more
Affected Products : ibtana- EPSS Score: %0.14
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-43446
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * (... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2020-26220
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version... Read more
Affected Products : touchbase.ai- EPSS Score: %0.20
- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-47612
DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-fai... Read more
Affected Products : datadump- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
3.5
LOWCVE-2019-19090
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.... Read more
Affected Products : esoms- EPSS Score: %0.11
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-6879
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request... Read more
- EPSS Score: %0.14
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-7881
The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a co... Read more
Affected Products : colorbox- EPSS Score: %0.13
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-22489
Flarum is a discussion platform for websites. If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission o... Read more
Affected Products : flarum- EPSS Score: %0.08
- Published: Jan. 13, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-6151
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.... Read more
Affected Products : tivoli_integrated_portal- EPSS Score: %0.23
- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025