Latest CVE Feed
-
3.5
LOWCVE-2010-4322
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.... Read more
Affected Products : vibe_onprem- Published: Jan. 07, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4355
Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.... Read more
Affected Products : dadabik- Published: Dec. 01, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13585
The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : ajax_search- Published: Feb. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2010-4427
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.0, 10.1.3.4.1, and 11.1.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4760
Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13261
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.... Read more
Affected Products : dam- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2010-0857
Unspecified vulnerability in the Oracle Workflow Cartridge component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-15103
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly acc... Read more
- Published: Jul. 27, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-2694
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.18 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multipl... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-3906
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.... Read more
Affected Products : gitlab- Published: Sep. 29, 2023
- Modified: May. 05, 2025
-
3.5
LOWCVE-2010-3581
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3512
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0u8 allows remote authenticated users to affect confidentiality, related to DAV (WebDAV).... Read more
Affected Products : sun_products_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4547
IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended a... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4425
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4807
Race condition in IBM Web Content Manager (WCM) 7.0.0.1 before CF003 allows remote authenticated users to cause a denial of service (infinite recursive query) via unspecified vectors, related to a StackOverflowError exception.... Read more
Affected Products : web_content_manager- Published: May. 26, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4624
MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created.... Read more
Affected Products : mybb- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-1525
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-22445
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2025-1523
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1131
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.... Read more
Affected Products : drupal- Published: Mar. 04, 2008
- Modified: Apr. 09, 2025