Latest CVE Feed
-
3.5
LOWCVE-2008-4530
Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote authenticated users with permissions to inject arbitrary web script or HTML via unspecified vectors related to posting of answers.... Read more
Affected Products : brilliant_gallery- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-5446
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from t... Read more
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-3830
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.... Read more
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-1467
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, Cal... Read more
Affected Products : unified_meetingplace call_manager vpn_client network_analysis_module acs_solution_engine ciscoworks ip_communicator meetingplace security_device_manager unified_meetingplace_express +8 more products- Published: Mar. 16, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-1947
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbi... Read more
Affected Products : firebug- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4427
Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote authenticated users to modify data on a server, related to encoding of cert... Read more
Affected Products : cache_database- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-3149
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect confidentiality, related to MySQL Client.... Read more
Affected Products : mysql- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-4523
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.p... Read more
Affected Products : ripe_website_manager- Published: Aug. 25, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6775
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.... Read more
Affected Products : acftp- Published: Dec. 27, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6821
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified... Read more
Affected Products : enews- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4927
axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.... Read more
Affected Products : 207w_network_camera- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-49578
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confidentiality or Integr... Read more
Affected Products : cloud_connector- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-4413
Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote authenticated users to inject arbitrary PHP code into an unspecified file via a new_entry value in the do parameter.... Read more
Affected Products : deskpro- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-2909
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-55455
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.... Read more
Affected Products : dootask- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2012-3445
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set ... Read more
Affected Products : libvirt- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-6512
Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter.... Read more
Affected Products : winamp_web_interface- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-0713
Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors.... Read more
- Published: Aug. 24, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-1981
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that... Read more
Affected Products : gitlab- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-43295
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.... Read more
Affected Products : passwordstate- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024