Latest CVE Feed
-
3.5
LOWCVE-2012-5339
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.... Read more
Affected Products : phpmyadmin- EPSS Score: %0.26
- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-5026
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method... Read more
- EPSS Score: %0.35
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-2694
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.18 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multipl... Read more
- EPSS Score: %0.59
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-3720
Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter.... Read more
- EPSS Score: %0.33
- Published: May. 31, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-6121
Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote auth... Read more
- EPSS Score: %0.19
- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2006-6514
Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of t... Read more
Affected Products : winamp_web_interface- EPSS Score: %0.56
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-8521
Cross-site scripting (XSS) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.10
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-7286
IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.... Read more
- EPSS Score: %0.34
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5942
Cross-site scripting (XSS) vulnerability in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject content, and conduct phishing attacks... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.19
- Published: Mar. 06, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4938
Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the banner message.... Read more
Affected Products : pattern_insight- EPSS Score: %0.36
- Published: Nov. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-6536
Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.23
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2006-6513
The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneou... Read more
Affected Products : winamp_web_interface- EPSS Score: %0.58
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-4007
Cross-site scripting (XSS) vulnerability in adv_sw.php in the Advanced Management Module (AMM) with firmware BBET before BBET64G and BPET before BPET64G for IBM BladeCenter systems allows remote attackers to inject arbitrary web script or HTML via unspeci... Read more
- EPSS Score: %0.20
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0840
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rational_focal_point- EPSS Score: %0.25
- Published: Feb. 26, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-2598
Unspecified vulnerability in the mobile app in Oracle Business Intelligence Enterprise Edition in Oracle Fusion Middleware before 11.1.1.7.0 (11.6.39) allows remote authenticated users to affect integrity via unknown vectors related to Mobile - iPad.... Read more
Affected Products : fusion_middleware- EPSS Score: %0.15
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4395
The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with certain permissions to obtain sensitive... Read more
Affected Products : hybridauth_social_login- EPSS Score: %0.17
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2019-19090
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.... Read more
Affected Products : esoms- EPSS Score: %0.11
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2025-1624
The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : gdpr_cookie_compliance- Published: Mar. 16, 2025
- Modified: Apr. 02, 2025
-
3.5
LOWCVE-2015-4392
Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-2.7 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to field display settings.... Read more
Affected Products : display_suite- EPSS Score: %0.20
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-43295
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.... Read more
Affected Products : passwordstate- EPSS Score: %0.29
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024