Latest CVE Feed
-
3.5
LOWCVE-2024-41839
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affec... Read more
- Published: Jul. 23, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-0112
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-0713
Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors.... Read more
- Published: Aug. 24, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0828
Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a crafted URI.... Read more
Affected Products : moinmoin- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5001
Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object... Read more
Affected Products : phpmyadmin- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5797
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integri... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4730
Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and conduct phishing attacks or obtain sensitive information via unknown vectors.... Read more
- Published: Nov. 11, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3865
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the p... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-1979
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.... Read more
Affected Products : build_of_quarkus- Published: Mar. 13, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-8481
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote... Read more
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2025-37108
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2022-20330
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-27601
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.... Read more
Affected Products : bigbluebutton- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-2220
The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : call_\/_chat_\/_contact_button- Published: May. 23, 2024
- Modified: May. 15, 2025
-
3.5
LOWCVE-2024-3920
The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : flattr- Published: May. 23, 2024
- Modified: May. 21, 2025
-
3.5
LOWCVE-2014-3012
Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.... Read more
Affected Products : curam_social_program_management- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-1810
FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.... Read more
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2021-26988
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Vi... Read more
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-2845
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily ... Read more
Affected Products : flexcube_investor_servicing- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-2260
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.... Read more
Affected Products : ajenti- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025