Latest CVE Feed
-
3.5
LOWCVE-2020-14525
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
3.5
LOWCVE-2010-3512
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0u8 allows remote authenticated users to affect confidentiality, related to DAV (WebDAV).... Read more
Affected Products : sun_products_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0697
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML vi... Read more
- Published: Feb. 23, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2697
Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are ... Read more
Affected Products : community_software- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-4830
Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or HTML via the (1) listing_title, (2) description, (3) homeurl (aka... Read more
- Published: Dec. 15, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0460
Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) i... Read more
- Published: Jan. 28, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0857
Unspecified vulnerability in the Oracle Workflow Cartridge component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-22445
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2025-1523
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1525
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2013-1566
Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more
Affected Products : mysql- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4255
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which all... Read more
- Published: Oct. 11, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4004
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_application_server- Published: Aug. 21, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3812
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.... Read more
- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-5461
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request th... Read more
Affected Products : tomcat- Published: Oct. 15, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-3720
Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter.... Read more
- Published: May. 31, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-1244
Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199.... Read more
Affected Products : webex_social- Published: May. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4261
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as de... Read more
- Published: Oct. 29, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-1992
Cross-site scripting (XSS) vulnerability in the Messages functionality in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-1835
Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.... Read more
Affected Products : moodle- Published: Mar. 25, 2013
- Modified: Apr. 11, 2025