Latest CVE Feed
-
3.5
LOWCVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the projec... Read more
Affected Products : gitlab- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-1157
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged... Read more
Affected Products : gitlab- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-5646
Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.... Read more
- Published: Aug. 29, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-4963
Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 28, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-58248
nopCommerce before 4.80.0 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.... Read more
Affected Products : nopcommerce- Published: Apr. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Race Condition
-
3.5
LOWCVE-2009-2856
Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-dat... Read more
- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-3111
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-1762.... Read more
Affected Products : peoplesoft_products- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3164
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Publish Item.... Read more
Affected Products : e-business_suite- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3156
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.... Read more
Affected Products : mysql- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-4560
Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition.... Read more
- Published: Nov. 28, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-0706
IBM Scale Out Network Attached Storage (SONAS) 1.3 before 1.3.2.3 requires cleartext storage of LDAP credentials without recommending a less privileged LDAP account, which might allow attackers to obtain sensitive server information by leveraging root acc... Read more
Affected Products : scale_out_network_attached_storage- Published: Apr. 07, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1982
Cross-site scripting (XSS) vulnerability in my_admin/admin1_list_pages.php in SocialCMS 1.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the TR_title parameter in an edit action.... Read more
Affected Products : socialcms- Published: Apr. 05, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3179
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Tree Manager.... Read more
Affected Products : peoplesoft_products- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5339
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.... Read more
Affected Products : phpmyadmin- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-0904
The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a de... Read more
Affected Products : vino- Published: May. 10, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5200
Cross-site scripting (XSS) vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote authenticated users to inject arbitrary web script or HTML via unspecif... Read more
- Published: Mar. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3176
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Panel Processor.... Read more
Affected Products : peoplesoft_products- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3148
Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity, related to Wireless/WAP upload.... Read more
Affected Products : e-business_suite- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-11044
In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.... Read more
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-2693
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.... Read more
- Published: May. 16, 2007
- Modified: Apr. 09, 2025