Latest CVE Feed
-
3.5
LOWCVE-2010-5098
Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : typo3- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-1902
Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YC... Read more
Affected Products : ycb002_firmware ycb004_firmware ycw003_firmware ycb001_firmware ycblhd5_firmware ycbl03_firmware ycbl03 ycblb3_firmware ycblb3 ycw001_firmware +20 more products- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6232
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.... Read more
Affected Products : spagobi- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-4369
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact fo... Read more
Affected Products : drupal- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3091
Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : taxonomy_autotagger_module- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-1988
The Phone Messages feature in Cybozu Garoon 2.0.0 through 3.7 SP2 allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.... Read more
Affected Products : garoon- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-1925
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.... Read more
Affected Products : ctools- Published: Jul. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2017-2161
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspeci... Read more
Affected Products : flashair- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2010-1810
FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.... Read more
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-32159
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.... Read more
Affected Products : infogami- Published: Jun. 22, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-3544
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Sky... Read more
Affected Products : moodle- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-52371
Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Feb. 18, 2024
- Modified: Dec. 04, 2024
-
3.5
LOWCVE-2010-2535
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.... Read more
Affected Products : joomla\!- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-23073
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter a... Read more
Affected Products : recipes- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-0474
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-27601
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.... Read more
Affected Products : bigbluebutton- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-8481
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote... Read more
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-44918
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : seacms- Published: Aug. 30, 2024
- Modified: Mar. 28, 2025
-
3.5
LOWCVE-2021-25014
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Store... Read more
Affected Products : ibtana- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-8077
Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors relat... Read more
Affected Products : newsflash- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025