Latest CVE Feed
-
3.5
LOWCVE-2014-0832
Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted t... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.17
- Published: Feb. 01, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-0416
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Roles & Privileges.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.36
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4669
HP Enterprise Maps 1.00 allows remote authenticated users to read arbitrary files via a WSDL document containing an XML external entity declaration in conjunction with an entity reference within a GetQuote operation, related to an XML External Entity (XXE... Read more
Affected Products : enterprise_maps- EPSS Score: %0.35
- Published: Jun. 28, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0894
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.... Read more
- EPSS Score: %10.74
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1451
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.... Read more
Affected Products : fortios- EPSS Score: %0.24
- Published: Feb. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0970
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links ... Read more
- EPSS Score: %0.15
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-1995
Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.21
- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-1992
Cross-site scripting (XSS) vulnerability in the Messages functionality in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.21
- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0915
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; ... Read more
- EPSS Score: %0.30
- Published: Jul. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3025
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; ... Read more
- EPSS Score: %0.21
- Published: Jul. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3009
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier... Read more
- EPSS Score: %0.14
- Published: Aug. 01, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3031
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : tivoli_business_service_manager- EPSS Score: %0.17
- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3069
Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticated users to inject arbitrary HTTP headers and conduct HT... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.16
- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6363
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuw88396.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.18
- Published: Nov. 12, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-2309
Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Jul. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2308
Cross-site scripting (XSS) vulnerability in the Taxonomy Grid : Catalog module for Drupal 6.x-1.6 and earlier allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.18
- Published: Jul. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4586
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permissio... Read more
- EPSS Score: %0.16
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-6064
Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be lever... Read more
Affected Products : cms_made_simple- EPSS Score: %0.90
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3035
Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : emptoris_spend_analysis- EPSS Score: %0.19
- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4934
TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.... Read more
Affected Products : tomatocart- EPSS Score: %0.40
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025