Latest CVE Feed
-
3.5
LOWCVE-2009-3206
Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated users, with "administer imagecache" permissions, to inject arbitrary web script ... Read more
- EPSS Score: %0.16
- Published: Sep. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-41663
Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of a slow-redirect Canarytoken can in... Read more
Affected Products : canarytokens- Published: Jul. 23, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-2381
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.... Read more
Affected Products : roller- EPSS Score: %0.20
- Published: Jun. 26, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-1983
Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : urbancode_build- EPSS Score: %0.17
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-8535
A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.... Read more
Affected Products : matrix_operating_environment- EPSS Score: %0.24
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-2729
Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects ta... Read more
Affected Products : ektron_content_management_system- EPSS Score: %0.18
- Published: Apr. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3227
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect integrity, rel... Read more
Affected Products : financial_services_software- EPSS Score: %0.19
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0942
Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability tha... Read more
- EPSS Score: %0.17
- Published: May. 01, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6914
Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.20
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-4226
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.... Read more
Affected Products : octopus_server- Published: Apr. 30, 2024
- Modified: Jun. 27, 2025
-
3.5
LOWCVE-2024-52507
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextclou... Read more
Affected Products : notes- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
3.5
LOWCVE-2013-1648
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via... Read more
Affected Products : open-xchange_server- EPSS Score: %0.41
- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-2031
Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.19
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3387
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Tools module before 7.x-1.4 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via a (1) node or (2) taxonomy term title.... Read more
Affected Products : taxonomy_tools- EPSS Score: %0.20
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3386
Cross-site scripting (XSS) vulnerability in the Node Access Product module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : node_access_product- EPSS Score: %0.21
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1969
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject a... Read more
Affected Products : tivoli_common_reporting- EPSS Score: %0.23
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3392
Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : ajax_timeline- EPSS Score: %0.23
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4345
Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during tab... Read more
Affected Products : phpmyadmin- EPSS Score: %0.21
- Published: Aug. 21, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-4078
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (... Read more
- EPSS Score: %0.24
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2015-3443
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbitrary web script or HTML via a password entry, which is not properly handle... Read more
Affected Products : secret_server- EPSS Score: %1.14
- Published: Jul. 02, 2015
- Modified: Apr. 12, 2025