Latest CVE Feed
-
3.5
LOWCVE-2020-12251
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, ob... Read more
Affected Products : gigavue- EPSS Score: %0.81
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-1762
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-3111.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.38
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-5491
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.... Read more
Affected Products : dynamic_display_block- EPSS Score: %0.18
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-4083
Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action to index.php. NOTE: some of these details are obtained f... Read more
Affected Products : brim- EPSS Score: %0.21
- Published: Sep. 15, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3993
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.25
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-ne... Read more
- EPSS Score: %0.76
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-3097
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.... Read more
Affected Products : tinytax_taxonomy_block_module- EPSS Score: %0.20
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-7229
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post t... Read more
Affected Products : twitter- EPSS Score: %0.16
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4384
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.x before 7.x-3.11 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unsp... Read more
Affected Products : ubercart_webform_checkout_pane- EPSS Score: %0.16
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4374
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a componen... Read more
Affected Products : webform- EPSS Score: %0.25
- Published: Jun. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4370
Cross-site scripting (XSS) vulnerability in the Site Documentation module before 6.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.... Read more
- EPSS Score: %0.15
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-1738
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."... Read more
- EPSS Score: %0.26
- Published: May. 20, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2011-1949
Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-201... Read more
Affected Products : plone- EPSS Score: %0.37
- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4425
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.... Read more
Affected Products : fusion_middleware- EPSS Score: %0.41
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-5833
Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web script or HTML via (1) user info (account details) or (2) a post.... Read more
Affected Products : bosmarket_business_directory_system- EPSS Score: %0.16
- Published: Nov. 05, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-9461
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_download action to wp-admin/admin-ajax.php.... Read more
Affected Products : cart66_lite- EPSS Score: %0.42
- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-3978
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment a... Read more
Affected Products : lightneasy- EPSS Score: %0.35
- Published: Oct. 04, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2008-1775
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details a... Read more
- EPSS Score: %0.21
- Published: Apr. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-5999
Cross-site scripting (XSS) vulnerability in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allows remote authenticated users, with create and edit permissions for posts, to inject arbitrary web script or HTML via unspecified vectors involving the... Read more
- EPSS Score: %0.16
- Published: Jan. 28, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-3476
Multiple cross-site scripting (XSS) vulnerabilities in (1) application/views/admin/layout.php and (2) themes/default/views/header.php in the Ushahidi Platform before 2.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors r... Read more
Affected Products : ushahidi_platform- EPSS Score: %0.16
- Published: Aug. 12, 2012
- Modified: Apr. 11, 2025