Latest CVE Feed
-
3.5
LOWCVE-2014-0465
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via unknown vectors related to Admin Console.... Read more
Affected Products : fusion_middleware- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3034
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to inject arbitrar... Read more
Affected Products : emptoris_contract_management- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0483
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to... Read more
- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3050
IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors.... Read more
Affected Products : rational_team_concert- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5541
Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-4826
bgpd in Quagga before 0.99.9 allows explicitly configured BGP peers to cause a denial of service (crash) via a malformed (1) OPEN message or (2) a COMMUNITY attribute, which triggers a NULL pointer dereference. NOTE: vector 2 only exists when debugging is... Read more
Affected Products : quagga- Published: Sep. 12, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-0910
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_portal- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-8105
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.... Read more
- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8960
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted fi... Read more
Affected Products : phpmyadmin- Published: Nov. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0598
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.... Read more
Affected Products : ubuntu_linux enterprise_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_eus mysql +6 more products- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2559
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.... Read more
- Published: Mar. 25, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0601
Unspecified vulnerability in Oracle MySQL 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Partition.... Read more
Affected Products : mysql- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-8602
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inse... Read more
Affected Products : token_insert_entity- Published: Dec. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1807
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.... Read more
- Published: Oct. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-37314
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-2814
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to... Read more
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-0385
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensi... Read more
Affected Products : websphere_application_server- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0412
Unspecified vulnerability in the PeopleSoft Enterprise SCM eProcurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Manage Requisition Status.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5622
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-inc... Read more
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0379
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.... Read more
Affected Products : websphere_mq- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025