Latest CVE Feed
-
3.5
LOWCVE-2014-2347
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.... Read more
Affected Products : misecuremessages- EPSS Score: %4.58
- Published: May. 06, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0874
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter.... Read more
Affected Products : content_navigator- EPSS Score: %0.19
- Published: Feb. 28, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6913
Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.23
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5939
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.19
- Published: Mar. 06, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-6494
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mango_automation- EPSS Score: %0.42
- Published: Oct. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3316
Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Requ... Read more
- EPSS Score: %0.19
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-3376
Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : quizzler- EPSS Score: %0.20
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3998
CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified ... Read more
Affected Products : infosphere_biginsights- EPSS Score: %0.17
- Published: Mar. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-0990
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email... Read more
Affected Products : dclassifieds- EPSS Score: %1.19
- Published: Feb. 07, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-9461
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_download action to wp-admin/admin-ajax.php.... Read more
Affected Products : cart66_lite- EPSS Score: %0.42
- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2021-40086
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from dir... Read more
Affected Products : ejbca- EPSS Score: %0.20
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2018-1392
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.16
- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-3384
Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : commerce_balanced_payments- EPSS Score: %0.21
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3392
Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : ajax_timeline- EPSS Score: %0.23
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8318
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML ... Read more
Affected Products : webform- EPSS Score: %0.27
- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0485
Unspecified vulnerability in the PeopleSoft Enterprise SCM Strategic Sourcing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.27
- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1040
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field in the editProfile form to index.php/home/profile; the (2... Read more
Affected Products : bedita- EPSS Score: %0.40
- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7980
Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML v... Read more
Affected Products : zen- EPSS Score: %0.23
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5221
The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by leveraging (1) publisher or (2) administrator privileges.... Read more
- EPSS Score: %0.19
- Published: Sep. 24, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5317
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mode parameter to cms/index.php.... Read more
Affected Products : ritecms- EPSS Score: %0.40
- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025