Latest CVE Feed
-
3.5
LOWCVE-2019-2547
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privil... Read more
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-10558
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: Mar. 24, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1775
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details a... Read more
- Published: Apr. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-2764
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors ("all fields").... Read more
Affected Products : absolute_live_support_xe- Published: Jun. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1941
Cross-site scripting (XSS) vulnerability in the profile update feature in Akiva WebBoard 8.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the form field. NOTE: the provenance of this information is u... Read more
Affected Products : webboard- Published: Apr. 25, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-2590
Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enterprise Manager 10.1.0.6 has unknown impact and remote authenticated attack vectors.... Read more
- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2019-20382
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.... Read more
- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2008-2105
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally... Read more
Affected Products : bugzilla- Published: May. 07, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-0810
Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.... Read more
Affected Products : skate_board- Published: Feb. 21, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-3331
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.... Read more
Affected Products : mantis- Published: Jul. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-2758
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute News Manager XE 3.2 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) pblname and (2) text parameters to (a) admin/search.asp, (3) name parame... Read more
Affected Products : absolute_news_manager_xe- Published: Jun. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-53862
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.... Read more
Affected Products : ansible_automation_platform- Published: Jul. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2024-13121
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1330
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the ... Read more
Affected Products : groupwise- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-0692
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili... Read more
Affected Products : simple_video_management_system- Published: Feb. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13314
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_htm... Read more
Affected Products : carousel\,_slider\,_gallery_by_wp_carousel- Published: Feb. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2006-7043
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gal... Read more
Affected Products : chipmunk_blogger- Published: Feb. 24, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-41946
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid crede... Read more
Affected Products : frugal_testing- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-1981
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that... Read more
Affected Products : gitlab- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to... Read more
Affected Products : vm_virtualbox- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025