Latest CVE Feed
-
3.5
LOWCVE-2015-7548
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a c... Read more
- Published: Jan. 12, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-7020
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the ... Read more
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-7561
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.... Read more
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2019-4271
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243.... Read more
Affected Products : websphere_application_server- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-52611
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions.... Read more
Affected Products : solarwinds_platform- Published: Feb. 11, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2015-4757
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-5000
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. ... Read more
Affected Products : openssh- Published: Apr. 05, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2067
Cross-site scripting (XSS) vulnerability in java/hudson/model/Cause.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to inject arbitrary web script or HTML via a "remote cause note."... Read more
Affected Products : jenkins- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0608
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF.... Read more
Affected Products : ubuntu_linux enterprise_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_eus mysql +6 more products- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2553
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to dynamic fields.... Read more
Affected Products : otrs- Published: Apr. 02, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-28838
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.... Read more
Affected Products : opencart- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-5698
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML vi... Read more
- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2571
Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web scri... Read more
Affected Products : moodle- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2512
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : documentum_eroom- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-1995
Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2005-3205
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the use... Read more
Affected Products : database_server- Published: Oct. 14, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2020-2769
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Web Based Report Designer). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access v... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2009-1971
Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : database_server- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2016-3009
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page... Read more
Affected Products : connections- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-1290
Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items... Read more
Affected Products : sharepoint_server- Published: Apr. 09, 2013
- Modified: Apr. 11, 2025