Latest CVE Feed
-
3.5
LOWCVE-2007-4204
Hitachi Groupmax Collaboration - Schedule, as used in Groupmax Collaboration Portal 07-32 through 07-32-/B, uCosminexus Collaboration Portal 06-32 through 06-32-/B, and Groupmax Collaboration Web Client - Mail/Schedule 07-32 through 07-32-/A, can assign s... Read more
- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4741
Cross-site scripting (XSS) vulnerability in admin/adminusers.php in Claroline before 1.8.6 allows remote authenticated administrators to inject arbitrary web script or HTML via the sort parameter. NOTE: the provenance of this information is unknown; the ... Read more
Affected Products : claroline- Published: Sep. 06, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4523
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.p... Read more
Affected Products : ripe_website_manager- Published: Aug. 25, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-1511
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13121
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-12173
The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : master_slider- Published: Feb. 19, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1484
The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate crea... Read more
Affected Products : punbb- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-48219
O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gpp field of a Cellular-Network-Info SIP header, aka an ECI (E-UTRAN Cell Iden... Read more
Affected Products :- Published: May. 18, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2025-1623
The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : gdpr_cookie_compliance- Published: Mar. 16, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1330
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the ... Read more
Affected Products : groupwise- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-0692
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili... Read more
Affected Products : simple_video_management_system- Published: Feb. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2021-2000
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having SYS Account privilege with network ac... Read more
Affected Products : database_server- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-36479
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet... Read more
- Published: Sep. 15, 2023
- Modified: May. 27, 2025
-
3.5
LOWCVE-2006-6775
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.... Read more
Affected Products : acftp- Published: Dec. 27, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-3011
Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafte... Read more
- Published: May. 08, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2006-6821
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified... Read more
Affected Products : enews- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-7043
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gal... Read more
Affected Products : chipmunk_blogger- Published: Feb. 24, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6512
Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter.... Read more
Affected Products : winamp_web_interface- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6514
Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of t... Read more
Affected Products : winamp_web_interface- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2020-14732
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024