Latest CVE Feed
-
3.5
LOWCVE-2025-42941
SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or maliciou... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2025-3635
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.... Read more
Affected Products : moodle- Published: Apr. 25, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2025-48219
O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gpp field of a Cellular-Network-Info SIP header, aka an ECI (E-UTRAN Cell Iden... Read more
Affected Products :- Published: May. 18, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2023-50458
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.... Read more
Affected Products : dradis- Published: Jul. 10, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2025-46546
In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx,... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
3.5
LOWCVE-2014-6151
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.... Read more
Affected Products : tivoli_integrated_portal- EPSS Score: %0.23
- Published: Oct. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-51337
Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/user_manage_editProcess.php.... Read more
Affected Products : gibbon- Published: Nov. 21, 2024
- Modified: Jul. 17, 2025
-
3.5
LOWCVE-2014-5276
Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.... Read more
- EPSS Score: %0.81
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-1370
Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.... Read more
Affected Products : anyconnect_secure_mobility_client- EPSS Score: %0.47
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-0743
Cross-site scripting (XSS) vulnerability in the edit account page in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote authenticated users to inject arbitrar... Read more
- EPSS Score: %0.23
- Published: Feb. 27, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-0857
Unspecified vulnerability in the Oracle Workflow Cartridge component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.38
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4432
Unspecified vulnerability in the Oracle Transportation Manager component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.38
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2023-3209
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.... Read more
Affected Products : mstore_api- EPSS Score: %0.07
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-5442
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users who attempt uploads, which allows remote authenticated users to upload unspecified files via unknown vectors.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.13
- Published: Oct. 14, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-4763
Cross-site scripting (XSS) vulnerability in Content Navigator in Content Engine in IBM FileNet Content Manager 5.2.x before 5.2.0.3-P8CPE-IF003 and Content Foundation 5.2.x before 5.2.0.3-P8CPE-IF003 allows remote authenticated users to inject arbitrary w... Read more
- EPSS Score: %0.21
- Published: Sep. 15, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-4036
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, al... Read more
- EPSS Score: %0.17
- Published: Nov. 27, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3034
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.19
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-0809
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the ... Read more
- EPSS Score: %0.19
- Published: Mar. 04, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-4199
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed)... Read more
Affected Products : plone- EPSS Score: %0.48
- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-5098
Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : typo3- EPSS Score: %0.39
- Published: May. 21, 2012
- Modified: Apr. 11, 2025