Latest CVE Feed
-
3.5
LOWCVE-2015-6753
Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) entity title, related to in-place ed... Read more
Affected Products : quick_edit- EPSS Score: %0.14
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3617
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces,... Read more
Affected Products : openbravo_erp- EPSS Score: %58.00
- Published: Nov. 02, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0371
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0.x, 7.3.1.x, 12.2.0, 12.2.1, and 12.2.2 allows remote authenticated users to affect integrity via unknown vectors r... Read more
- EPSS Score: %0.44
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0444
Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vuln... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.35
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-6620
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side reques... Read more
Affected Products :- Published: Jul. 29, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-37314
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-44918
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : seacms- Published: Aug. 30, 2024
- Modified: Mar. 28, 2025
-
3.5
LOWCVE-2021-39163
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limit... Read more
- EPSS Score: %0.27
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39164
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerabil... Read more
- EPSS Score: %0.50
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client appl... Read more
Affected Products : gitlab- EPSS Score: %0.25
- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-3624
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to app... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Oct. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-2677
Multiple cross-site scripting (XSS) vulnerabilities in ocPortal before 9.0.17 allow remote authenticated users to inject arbitrary web script or HTML via the (1) title or (2) text field in the cms_calendar page to cms/index.php; unspecified fields in (3) ... Read more
Affected Products : ocportal- EPSS Score: %0.26
- Published: Mar. 23, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-37438
In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown ... Read more
- EPSS Score: %0.28
- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-19090
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.... Read more
Affected Products : esoms- EPSS Score: %0.11
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-5509
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Difficult to exploit vulnerability allows l... Read more
Affected Products : flexcube_investor_servicing- EPSS Score: %0.25
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-3487
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploi... Read more
Affected Products : flexcube_investor_servicing- EPSS Score: %0.25
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2021-20761
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.... Read more
Affected Products : garoon- EPSS Score: %0.15
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2017-3490
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vu... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- EPSS Score: %0.25
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-6001
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.... Read more
Affected Products : forms_experience_builder- EPSS Score: %0.14
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2021-39220
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images... Read more
- EPSS Score: %0.26
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024