Latest CVE Feed
-
3.5
LOWCVE-2014-7830
Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML... Read more
Affected Products : moodle- EPSS Score: %0.21
- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8521
Cross-site scripting (XSS) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.10
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7295
The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via cr... Read more
Affected Products : mediawiki- EPSS Score: %0.31
- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7869
Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via... Read more
Affected Products : context_form_alteration_module- EPSS Score: %0.20
- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-30261
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) ... Read more
- Published: Apr. 04, 2024
- Modified: Dec. 18, 2024
-
3.5
LOWCVE-2020-4049
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity sel... Read more
- EPSS Score: %2.46
- Published: Jun. 12, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-1636
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint... Read more
- EPSS Score: %7.90
- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3363
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manager (UCM) 9.1(2.10000.28) allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq68443.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.32
- Published: Sep. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6474
Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED.... Read more
- EPSS Score: %0.37
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6592
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via vectors related to SAML, a different vulnerability than CVE-2015-0389.... Read more
- EPSS Score: %0.15
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5174
The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : netweaver_business_warehouse- EPSS Score: %0.45
- Published: Jul. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5438
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_com... Read more
- EPSS Score: %0.16
- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-4826
bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is... Read more
Affected Products : quagga- EPSS Score: %1.26
- Published: Sep. 12, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2020-3126
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multim... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.10
- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-8378
Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the "administer content types" or "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related t... Read more
Affected Products : tablefield- EPSS Score: %0.23
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0444
Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vuln... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.35
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2005-3205
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the use... Read more
Affected Products : database_server- EPSS Score: %0.46
- Published: Oct. 14, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2014-0431
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-5881.... Read more
Affected Products : mysql- EPSS Score: %0.66
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0915
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; ... Read more
- EPSS Score: %0.30
- Published: Jul. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2971
Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remote authenticated users to inject arbitrary web script or HTML via the description parameter.... Read more
Affected Products : icomplaints- EPSS Score: %0.34
- Published: Jul. 24, 2014
- Modified: Apr. 12, 2025