Latest CVE Feed
-
3.5
LOWCVE-2015-6805
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.... Read more
Affected Products : mdc_private_message- Published: Sep. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-0124
Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for p... Read more
Affected Products : drupal- Published: Jan. 09, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3782
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field und... Read more
Affected Products : acg_ptp- Published: Aug. 26, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-5365
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "What's going on?" profile field.... Read more
Affected Products : zurmo_crm- Published: Jul. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-2065
Cross-site scripting (XSS) vulnerability in the Language Icons module 6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with administer languages permissions to inject arbitrary web script or HTML via unspecifi... Read more
- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-7227
The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.... Read more
Affected Products : fieldable_panels_panes- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2019-2845
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily ... Read more
Affected Products : flexcube_investor_servicing- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-5871
Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vuln... Read more
Affected Products : supply_chain_products_suite- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-3591
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editin... Read more
Affected Products : phpmyadmin- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3012
Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.... Read more
Affected Products : curam_social_program_management- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2003-1570
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations ... Read more
Affected Products : tivoli_storage_manager- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-6487
Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect integrity via unknown vectors related to End User Self Service.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6525
Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Tem... Read more
Affected Products : e-business_suite- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-46168
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users inside ... Read more
Affected Products : discourse- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-11140
The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter... Read more
Affected Products : real_wp_shop_lite_ajax_ecommerce_shopping_cart- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2023-6251
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users.... Read more
- Published: Nov. 24, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2009-2919
Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.... Read more
Affected Products : orca- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-2310
Cross-site scripting (XSS) vulnerability in the cctags module for Drupal 6.x-1.x before 6.x-1.10 and 7.x-1.x before 7.x-1.10 allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-9362
Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web scri... Read more
Affected Products : meta_tags_quick- Published: Dec. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8744
Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrary web script or HTML via an image title.... Read more
Affected Products : nivo_slider- Published: Oct. 13, 2014
- Modified: Apr. 12, 2025