Latest CVE Feed
-
3.5
LOWCVE-2022-29820
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible... Read more
Affected Products : pycharm- Published: Apr. 28, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-33000
SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-3192
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity, related to Rich Text Editor (RTE).... Read more
Affected Products : peoplesoft_products- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-23074
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged... Read more
Affected Products : recipes- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-30107
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. ... Read more
Affected Products : connections- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-0932
Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- Published: Apr. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4065
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to bypass unspecified authorization checks and obtain direct access to a (1) Cloud Controller or (2) Walrus serv... Read more
Affected Products : eucalyptus- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1676
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual... Read more
Affected Products : financial_services_software- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2023-4654
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.... Read more
- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-0913
Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : easyctf- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-3454
An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed t... Read more
Affected Products : matter- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-9017
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field in a Task to frontend/index.jsp.... Read more
Affected Products : openkm- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4139
Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php.... Read more
Affected Products : wp_smiley- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2592
Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerabili... Read more
Affected Products : hyperion- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-41663
Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of a slow-redirect Canarytoken can in... Read more
Affected Products : canarytokens- Published: Jul. 23, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-3209
The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.... Read more
Affected Products : mstore_api- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-4036
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, al... Read more
- Published: Nov. 27, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-0521
Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the ... Read more
- Published: Mar. 12, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-0535
Multiple cross-site scripting (XSS) vulnerabilities in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 02, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4199
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed)... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025