Latest CVE Feed
-
3.5
LOWCVE-2015-2289
Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when cre... Read more
Affected Products : serendipity- EPSS Score: %0.34
- Published: Mar. 23, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-5502
Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : plone- EPSS Score: %0.15
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-1994
Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.21
- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8748
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.... Read more
Affected Products : doubleclick_for_publishers- EPSS Score: %0.20
- Published: Oct. 13, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-2083
Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy te... Read more
- EPSS Score: %0.23
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-4022
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenti... Read more
- EPSS Score: %0.14
- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-2086
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.... Read more
Affected Products : panopoly_magic- EPSS Score: %0.21
- Published: Feb. 26, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1516
Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : realpresence_cloudaxis_suite- EPSS Score: %0.16
- Published: Sep. 03, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4132
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.28
- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-3591
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editin... Read more
Affected Products : phpmyadmin- EPSS Score: %0.18
- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3989
IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the ... Read more
Affected Products : security_appscan- EPSS Score: %0.16
- Published: Oct. 25, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-6805
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.... Read more
Affected Products : mdc_private_message- EPSS Score: %0.24
- Published: Sep. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-1829
Multiple cross-site scripting (XSS) vulnerabilities in AutoFORM PDM Archive before 6.920 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields.... Read more
Affected Products : autoform_pdm_archive- EPSS Score: %0.39
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-4392
Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-2.7 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to field display settings.... Read more
Affected Products : display_suite- EPSS Score: %0.20
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2197
Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.... Read more
Affected Products : entity_api- EPSS Score: %0.21
- Published: Mar. 03, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-5666
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.... Read more
Affected Products : winftp_ftp_server- EPSS Score: %63.29
- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-8913
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vu... Read more
Affected Products : business_process_manager- EPSS Score: %0.23
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-2535
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.... Read more
Affected Products : joomla\!- EPSS Score: %0.02
- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-8916
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vul... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.17
- Published: Oct. 03, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-2610
Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.... Read more
- EPSS Score: %0.34
- Published: Jul. 27, 2009
- Modified: Apr. 09, 2025