Latest CVE Feed
-
3.5
LOWCVE-2014-3075
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.... Read more
- Published: Sep. 04, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-1368
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modifi... Read more
Affected Products : drupal_project_issue_tracking- Published: Mar. 09, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-ne... Read more
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-5833
Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web script or HTML via (1) user info (account details) or (2) a post.... Read more
Affected Products : bosmarket_business_directory_system- Published: Nov. 05, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-1762
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-3111.... Read more
Affected Products : peoplesoft_products- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-2079
Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use ... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-1738
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."... Read more
- Published: May. 20, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-2698
Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOT... Read more
Affected Products : community_software- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-8318
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML ... Read more
Affected Products : webform- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-4717
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUse... Read more
Affected Products : claroline- Published: Sep. 05, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2020-12251
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, ob... Read more
Affected Products : gigavue- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-0279
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users... Read more
Affected Products : anycomment- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-3803
Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related t... Read more
Affected Products : hyperion- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0684
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.... Read more
Affected Products : activemq- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2016-0473
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-39061
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.... Read more
- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-30950
A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.... Read more
Affected Products : fudforum- Published: Apr. 17, 2024
- Modified: Jun. 10, 2025
-
3.5
LOWCVE-2021-2159
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-45715
The console may experience a service interruption when processing file names with invalid characters. ... Read more
Affected Products : bigfix_platform- Published: Mar. 28, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2025-1062
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered... Read more
Affected Products : slider\,_gallery\,_and_carousel- Published: Mar. 24, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Cross-Site Scripting