Latest CVE Feed
-
3.5
LOWCVE-2009-2327
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.... Read more
Affected Products : kervinet_forum- Published: Jul. 05, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3653
Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permission, to inject arbitrary web script or HTML via unspecif... Read more
- Published: Oct. 09, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-2048
Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script... Read more
Affected Products : crs customer_response_applications ip_qm unified_ccx unified_ip_contact_center_express unified_ip_ivr- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-5026
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-si... Read more
Affected Products : sharepoint_server- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-2083
Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy te... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-0817
Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML... Read more
- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-5446
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from t... Read more
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3157
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web script or HTML via the title of a content type.... Read more
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1484
The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate crea... Read more
Affected Products : punbb- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-57611
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2024-12173
The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : master_slider- Published: Feb. 19, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-3513
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : sureforms- Published: May. 02, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1131
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.... Read more
Affected Products : drupal- Published: Mar. 04, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-3559
The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to re... Read more
Affected Products : enterprise_virtualization- Published: Aug. 06, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5240
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to star... Read more
- Published: Oct. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-28838
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.... Read more
Affected Products : opencart- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-3949
Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vect... Read more
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3475
Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user emai... Read more
- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-11058
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fi... Read more
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-2769
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Web Based Report Designer). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access v... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024