Latest CVE Feed
-
3.5
LOWCVE-2023-36479
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet... Read more
- Published: Sep. 15, 2023
- Modified: May. 27, 2025
-
3.5
LOWCVE-2009-0359
Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.... Read more
Affected Products : samizdat- Published: Feb. 17, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3653
Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permission, to inject arbitrary web script or HTML via unspecif... Read more
- Published: Oct. 09, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3652
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbi... Read more
- Published: Oct. 09, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3891
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).... Read more
Affected Products : wordpress- Published: Nov. 17, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-0603
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the H... Read more
- Published: Feb. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-1461
Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Page Title field.... Read more
Affected Products : razorcms- Published: Apr. 28, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-0155
CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HT... Read more
- Published: Sep. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-3782
Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.... Read more
- Published: Oct. 26, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3648
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content ... Read more
- Published: Oct. 09, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-0081
Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2381.... Read more
Affected Products : fusion_middleware- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-5062
IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.... Read more
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-5059
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.10 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by checking out a document that is accessed through a connector, aka SPR MMOI7PS... Read more
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-2632
Cross-site scripting (XSS) vulnerability in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via file descriptions.... Read more
Affected Products : bytehoard- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2009-2610
Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.... Read more
- Published: Jul. 27, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-7286
IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.... Read more
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13123
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for exa... Read more
Affected Products : advanced_form_integration- Published: Mar. 25, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-51385
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.... Read more
- Published: Jul. 31, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
3.5
LOWCVE-2024-13122
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for exa... Read more
Affected Products : advanced_form_integration- Published: Mar. 25, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-12683
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : smart_maintenance_mode- Published: Mar. 26, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting