Latest CVE Feed
-
3.5
LOWCVE-2015-3381
Cross-site scripting (XSS) vulnerability in the Node basket module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : node_basket- EPSS Score: %0.21
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0122
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different v... Read more
Affected Products : rational_team_concert- EPSS Score: %0.19
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-2037
Multiple cross-site scripting (XSS) vulnerabilities in EditeurScripts EsContacts 1.0 allow remote authenticated users to inject arbitrary web script or HTML via the msg parameter to (1) login.php, (2) importer.php, (3) add_groupe.php, (4) contacts.php, (5... Read more
Affected Products : escontacts- EPSS Score: %0.23
- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-9097
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.... Read more
Affected Products : manageengine_endpoint_central- Published: Feb. 05, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2017-3598
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privil... Read more
Affected Products : webcenter_sites- EPSS Score: %0.23
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2007-4412
Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (1) techs.php, (2) ticket_category.php, (3) ticket_priority.php,... Read more
Affected Products : deskpro- EPSS Score: %0.20
- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2021-3716
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the serve... Read more
- EPSS Score: %0.05
- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-45486
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.... Read more
- EPSS Score: %0.01
- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2009-0240
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.... Read more
Affected Products : websvn- EPSS Score: %0.41
- Published: Jan. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-33229
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML. ... Read more
Affected Products : solarwinds_platform- EPSS Score: %0.80
- Published: Jul. 26, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-5025
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.... Read more
- EPSS Score: %0.45
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-8001
The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk t... Read more
Affected Products : mediawiki- EPSS Score: %0.39
- Published: Nov. 09, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0385
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensi... Read more
Affected Products : websphere_application_server- EPSS Score: %0.30
- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-6074
Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to ... Read more
- EPSS Score: %0.22
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2169
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.... Read more
Affected Products : rational_clearquest- EPSS Score: %0.19
- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2019-2738
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows low privileged atta... Read more
- EPSS Score: %0.67
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-5061
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter t... Read more
Affected Products : manageengine_assetexplorer- EPSS Score: %0.29
- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-1580
The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.... Read more
Affected Products : mediawiki- EPSS Score: %0.59
- Published: Apr. 27, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2604
Multiple cross-site scripting (XSS) vulnerabilities in GuestAccess.jsp in the Guest/Contractor access component in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote authenticated users to inject arbitrary web script or HTML... Read more
- EPSS Score: %0.34
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-0513
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged acc... Read more
- EPSS Score: %0.18
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025