Latest CVE Feed
-
3.5
LOWCVE-2015-0139
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6039
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content in an Office Marketplace instance, aka "Micros... Read more
- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2017-5930
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.... Read more
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2015-0507
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.... Read more
Affected Products : mysql- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2018-16968
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.... Read more
Affected Products : sharefile_storagezones_controller- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-4765
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via vectors related to OAM Dashboard.... Read more
Affected Products : e-business_suite- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-2035
When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consid... Read more
Affected Products : pan-os- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39164
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerabil... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-2336
Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Creat... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39163
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limit... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-26127
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and aff... Read more
- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-36479
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet... Read more
- Published: Sep. 15, 2023
- Modified: May. 27, 2025
-
3.5
LOWCVE-2024-41839
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affec... Read more
- Published: Jul. 23, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2008-1484
The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate crea... Read more
Affected Products : punbb- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-13121
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-53862
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.... Read more
Affected Products : ansible_automation_platform- Published: Jul. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2024-13314
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_htm... Read more
Affected Products : carousel\,_slider\,_gallery_by_wp_carousel- Published: Feb. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1330
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the ... Read more
Affected Products : groupwise- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-0692
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili... Read more
Affected Products : simple_video_management_system- Published: Feb. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-5999
Cross-site scripting (XSS) vulnerability in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allows remote authenticated users, with create and edit permissions for posts, to inject arbitrary web script or HTML via unspecified vectors involving the... Read more
- Published: Jan. 28, 2009
- Modified: Apr. 09, 2025