Latest CVE Feed
-
3.5
LOWCVE-2015-2639
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Firewall.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2645
Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4540
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 and 6.9.x before 6.9.1 P6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rsa_identity_management_and_governance- Published: Sep. 26, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6037
Cross-site scripting (XSS) vulnerability in Microsoft Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, and SharePoint Foundation 2013 SP1 allows remote authentica... Read more
- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2677
Multiple cross-site scripting (XSS) vulnerabilities in ocPortal before 9.0.17 allow remote authenticated users to inject arbitrary web script or HTML via the (1) title or (2) text field in the cms_calendar page to cms/index.php; unspecified fields in (3) ... Read more
Affected Products : ocportal- Published: Mar. 23, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5304
Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified v... Read more
Affected Products : jboss_enterprise_application_platform- Published: Dec. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-2998
frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code.... Read more
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3381
Cross-site scripting (XSS) vulnerability in the Node basket module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : node_basket- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-4019
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : maximo_asset_management- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-49760
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +4 more products- Published: Jul. 08, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2013-1541
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.0.2 through 5.0.5, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality via vectors relat... Read more
Affected Products : financial_services_software- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2016-8942
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2013-2042
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the url parameter to (1) apps/bookmarks/ajax/addBookmark... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-1424
The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to... Read more
- Published: May. 24, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-0836
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC.... Read more
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-1549
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 5.3.3, 6.0.1, and 12.0.0 allows remote authenticated users to affect integrity via vectors related to BASE.... Read more
Affected Products : financial_services_software- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-0442
The service utility in EMC Avamar 5.x before 5.0.4 uses cleartext to transmit event details in (1) service requests and (2) e-mail messages, which might allow remote attackers to obtain sensitive information by sniffing the network.... Read more
Affected Products : avamar- Published: Mar. 16, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-3353
Cross-site scripting (XSS) vulnerability in the Field Display Label module before 7.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the alternate field label in content types settings.... Read more
Affected Products : field_display_label- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-2364
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression... Read more
Affected Products : moodle- Published: Jul. 21, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-3514
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : sureforms- Published: May. 02, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting