Latest CVE Feed
-
3.5
LOWCVE-2012-2310
Cross-site scripting (XSS) vulnerability in the cctags module for Drupal 6.x-1.x before 6.x-1.10 and 7.x-1.x before 7.x-1.10 allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-55416
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.... Read more
Affected Products : voyager- Published: Jan. 30, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-30700
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to com... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2025-31494
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The AutoGPT Platform's WebSocket API transmitted node execution updates to subscribers based on the graph_id+g... Read more
- Published: Apr. 15, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2025-27430
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Server-Side Request Forgery
-
3.5
LOWCVE-2021-45916
The programming function of Shockwall system has an improper input validation vulnerability. An authenticated attacker within the local area network can send malicious response to the server to disrupt the service partially.... Read more
Affected Products : shenwang_endpoint_protection_security_system- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-40086
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from dir... Read more
Affected Products : ejbca- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-45486
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.... Read more
- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-42700
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.... Read more
Affected Products : inkscape- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-51749
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a fi... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
3.5
LOWCVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client appl... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-8897
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 b... Read more
- Published: Dec. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8078
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject... Read more
Affected Products : print- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-5055
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting ... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-7386
Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Medi... Read more
Affected Products : gallery_-_photo_albums_-_portfolio- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-3993
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-8318
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML ... Read more
Affected Products : webform- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-ne... Read more
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5500
Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : navigate- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2018-3184
Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: IQR - Foundation Services). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to ... Read more
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024