Latest CVE Feed
-
3.5
LOWCVE-2013-0129
Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" field or (2) the body of an e-mail autoresponder message... Read more
Affected Products : pd-admin- Published: Apr. 19, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6913
Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2370
Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data.... Read more
- Published: Jul. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-5939
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Mar. 06, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4584
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not properly encrypt system-backup data, which makes it easier for remote authenticated users to obtain sensitive in... Read more
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-30259
The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for inst... Read more
Affected Products :- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2015-0130
Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.... Read more
- Published: Jul. 20, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-4371
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web... Read more
Affected Products : drupal- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-4848
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (... Read more
Affected Products : lotus_foundations_start- Published: Dec. 19, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-0090
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web, a different vulnerability than CVE-2012-0092.... Read more
Affected Products : fusion_middleware- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2670
Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.... Read more
Affected Products : manageengine_opstor- Published: Mar. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-44718
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. Th... Read more
Affected Products : ngeniusone- Published: Jan. 27, 2023
- Modified: Mar. 28, 2025
-
3.5
LOWCVE-2017-3320
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.7.16 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via... Read more
Affected Products : mysql- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2024-54681
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2005-3310
Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by... Read more
Affected Products : phpbb- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2022-45393
A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.... Read more
Affected Products : delete_log- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
3.5
LOWCVE-2024-57159
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2009-4963
Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 28, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0684
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.... Read more
Affected Products : activemq- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4065
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to bypass unspecified authorization checks and obtain direct access to a (1) Cloud Controller or (2) Walrus serv... Read more
Affected Products : eucalyptus- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025