Latest CVE Feed
-
3.5
LOWCVE-2013-5420
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.... Read more
Affected Products : security_access_manager_for_enterprise_single_sign-on- EPSS Score: %0.16
- Published: Dec. 23, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-7194
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.... Read more
Affected Products : efront- EPSS Score: %0.40
- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-7726
Cross-site scripting (XSS) vulnerability in role deletion in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allows remote authenticated users to inject arbitrary web script or HTML via the role name, aka SAP Security Note 215389... Read more
Affected Products : hana- EPSS Score: %0.18
- Published: Oct. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7728
Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security No... Read more
Affected Products : hana- EPSS Score: %0.18
- Published: Oct. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5404
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other p... Read more
- EPSS Score: %0.17
- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-4892
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-4917.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.15
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6237
The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.... Read more
- EPSS Score: %0.44
- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-6354
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuv73338.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.28
- Published: Oct. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-5941
Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.... Read more
Affected Products : netezza- EPSS Score: %0.17
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3322
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.... Read more
- EPSS Score: %0.19
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-1451
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.... Read more
Affected Products : fortios- EPSS Score: %0.24
- Published: Feb. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0416
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Roles & Privileges.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.36
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy Configuration... Read more
- EPSS Score: %21.08
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0123
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different v... Read more
Affected Products : rational_team_concert- EPSS Score: %0.19
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7978
Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.... Read more
Affected Products : bluemasters- EPSS Score: %0.23
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3903
Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via crafted Exif data.... Read more
Affected Products : cakifo- EPSS Score: %0.18
- Published: Aug. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-6064
Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be lever... Read more
Affected Products : cms_made_simple- EPSS Score: %0.90
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4934
TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.... Read more
Affected Products : tomatocart- EPSS Score: %0.40
- Published: Oct. 31, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-1979
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.... Read more
Affected Products : build_of_quarkus- Published: Mar. 13, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2011-3591
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editin... Read more
Affected Products : phpmyadmin- EPSS Score: %0.18
- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025