Latest CVE Feed
-
3.5
LOWCVE-2020-14732
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-5301
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP ... Read more
Affected Products : simplesamlphp- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-47612
DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-fai... Read more
Affected Products : datadump- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
3.5
LOWCVE-2024-43446
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * (... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2015-8481
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote... Read more
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-44918
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : seacms- Published: Aug. 30, 2024
- Modified: Mar. 28, 2025
-
3.5
LOWCVE-2024-3920
The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : flattr- Published: May. 23, 2024
- Modified: May. 21, 2025
-
3.5
LOWCVE-2024-2220
The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : call_\/_chat_\/_contact_button- Published: May. 23, 2024
- Modified: May. 15, 2025
-
3.5
LOWCVE-2024-32236
An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.... Read more
Affected Products : cmseasy- Published: Apr. 25, 2024
- Modified: Apr. 14, 2025
-
3.5
LOWCVE-2024-39846
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.... Read more
Affected Products :- Published: Jun. 29, 2024
- Modified: Nov. 25, 2024
-
3.5
LOWCVE-2024-10710
The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : yadisk_files- Published: Nov. 25, 2024
- Modified: May. 15, 2025
-
3.5
LOWCVE-2020-10368
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
3.5
LOWCVE-2022-24744
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.... Read more
Affected Products : shopware- Published: Mar. 09, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-5509
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Difficult to exploit vulnerability allows l... Read more
Affected Products : flexcube_investor_servicing- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2021-39220
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images... Read more
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-29066
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-1451
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.... Read more
Affected Products : fortios- Published: Feb. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-2404
Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors related to Account.... Read more
Affected Products : e-business_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3009
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier... Read more
- Published: Aug. 01, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3322
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.... Read more
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025