Latest CVE Feed
-
3.5
LOWCVE-2017-18436
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-3069
Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1) UserName or (2) Password to the NAS User Setup page, (3) deviceName to USB_a... Read more
- Published: Apr. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3012
Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.... Read more
Affected Products : curam_social_program_management- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7227
The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.... Read more
Affected Products : fieldable_panels_panes- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-2065
Cross-site scripting (XSS) vulnerability in the Language Icons module 6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with administer languages permissions to inject arbitrary web script or HTML via unspecifi... Read more
- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0177
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web sc... Read more
- Published: Jan. 30, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-6149
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system... Read more
- Published: Feb. 14, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3089
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.... Read more
Affected Products : mailman- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1370
Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.... Read more
Affected Products : anyconnect_secure_mobility_client- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1344
Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID ... Read more
Affected Products : ios- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0172
Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifyi... Read more
Affected Products : samba- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-0904
The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a de... Read more
Affected Products : vino- Published: May. 10, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-3629
Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject arbitrary web script or HTML via un... Read more
Affected Products : typo3- Published: Nov. 02, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-23557
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack. ... Read more
Affected Products : connections- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-5339
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.... Read more
Affected Products : phpmyadmin- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5761
Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : netezza- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1679
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.... Read more
Affected Products : financial_services_software- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1588
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via ... Read more
Affected Products : drupal- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0672
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.... Read more
Affected Products : wincc_tia_portal- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5762
Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject arbitrary web script or HTML via vectors involving the MHTML protocol.... Read more
Affected Products : netezza- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025