Latest CVE Feed
-
3.5
LOWCVE-2015-3357
Cross-site scripting (XSS) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "access wishlists" permission to inject arbitrary web script or HTML via unspecified vectors, w... Read more
Affected Products : wishlist- EPSS Score: %0.20
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3617
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces,... Read more
Affected Products : openbravo_erp- EPSS Score: %58.00
- Published: Nov. 02, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3044
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting-attendance privileges.... Read more
- EPSS Score: %0.15
- Published: Nov. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-3344
Cross-site scripting (XSS) vulnerability in the Course module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : course- EPSS Score: %0.23
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3045
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function.... Read more
- EPSS Score: %0.15
- Published: Nov. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6307
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.19
- Published: Nov. 29, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6237
The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.... Read more
- EPSS Score: %0.44
- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5404
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other p... Read more
- EPSS Score: %0.17
- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-0416
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Roles & Privileges.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.36
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5452
IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an X... Read more
Affected Products : filenet_business_process_framework- EPSS Score: %0.30
- Published: Dec. 19, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-7194
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.... Read more
Affected Products : efront- EPSS Score: %0.40
- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5420
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.... Read more
Affected Products : security_access_manager_for_enterprise_single_sign-on- EPSS Score: %0.16
- Published: Dec. 23, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5390
Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.19
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3014
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- EPSS Score: %0.19
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0925
Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.... Read more
Affected Products : sterling_control_center- EPSS Score: %0.14
- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3933
Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via an address field.... Read more
Affected Products : addressfield_tokens- EPSS Score: %0.20
- Published: Jun. 02, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5690
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite before 7.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) content with the text/xml MIME type or (2) the Status comment field of an appointment... Read more
Affected Products : open-xchange_appsuite- EPSS Score: %0.16
- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-6363
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuw88396.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.18
- Published: Nov. 12, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3186
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.... Read more
Affected Products : ambari- EPSS Score: %0.20
- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0370
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.... Read more
Affected Products : forms_experience_builder- EPSS Score: %0.16
- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025