Latest CVE Feed
-
3.5
LOWCVE-2016-6539
The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in reverse. The MAC address can be obtained by being in close proximity to the Bluetooth device, effectively exposing the device ID. The ID can... Read more
- EPSS Score: %0.16
- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2025-49462
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.... Read more
Affected Products : zoom- Published: Jul. 10, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2016-3531
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to PC / Notification.... Read more
- EPSS Score: %0.30
- Published: Jul. 21, 2016
- Modified: May. 08, 2025
-
3.5
LOWCVE-2016-2998
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.... Read more
Affected Products : connections- EPSS Score: %0.05
- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-3009
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page... Read more
Affected Products : connections- EPSS Score: %0.04
- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0347
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotf... Read more
- EPSS Score: %0.21
- Published: Apr. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8960
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted fi... Read more
Affected Products : phpmyadmin- EPSS Score: %0.29
- Published: Nov. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5739
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mim... Read more
Affected Products : wordpress- EPSS Score: %0.30
- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-6336
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecifi... Read more
Affected Products : exchange_server- EPSS Score: %3.80
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-37314
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-7561
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.... Read more
- EPSS Score: %0.14
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2015-1807
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.... Read more
- EPSS Score: %0.16
- Published: Oct. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6808
Cross-site scripting (XSS) vulnerability in the Spotlight module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : spotlight- EPSS Score: %0.14
- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3551
Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary w... Read more
Affected Products : moodle- EPSS Score: %0.34
- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2329
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2) crafted request to a moni... Read more
Affected Products : check_mk- EPSS Score: %0.16
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6815
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vec... Read more
Affected Products : ubuntu_linux enterprise_linux fedora openstack qemu xen eos suse_linux_enterprise_desktop suse_linux_enterprise_server suse_linux_enterprise_software_development_kit +1 more products- EPSS Score: %1.90
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-8602
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inse... Read more
Affected Products : token_insert_entity- EPSS Score: %0.12
- Published: Dec. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0370
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.... Read more
Affected Products : forms_experience_builder- EPSS Score: %0.16
- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7548
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a c... Read more
- EPSS Score: %0.17
- Published: Jan. 12, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2559
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.... Read more
- EPSS Score: %0.27
- Published: Mar. 25, 2015
- Modified: Apr. 12, 2025