Latest CVE Feed
-
3.5
LOWCVE-2023-33229
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML. ... Read more
Affected Products : solarwinds_platform- Published: Jul. 26, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-4913
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.... Read more
Affected Products : ubuntu_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_tus mysql +5 more products- Published: Oct. 22, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5061
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter t... Read more
Affected Products : manageengine_assetexplorer- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4769
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5354
plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a d... Read more
- Published: Dec. 16, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2017-2603
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).... Read more
Affected Products : jenkins- Published: May. 15, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-5953
Cross-site scripting (XSS) vulnerability in the activity application in ownCloud Server before 7.0.5 and 8.0.x before 8.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a " (double quote) character in a filename in a shared... Read more
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-0827
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.... Read more
Affected Products : drupal- Published: Oct. 28, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-4955
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web s... Read more
Affected Products : phpmyadmin- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4791
Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."... Read more
Affected Products : exchange_server- Published: Dec. 12, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-44718
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. Th... Read more
Affected Products : ngeniusone- Published: Jan. 27, 2023
- Modified: Mar. 28, 2025
-
3.5
LOWCVE-2022-45393
A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.... Read more
Affected Products : delete_log- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
3.5
LOWCVE-2017-3320
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.7.16 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via... Read more
Affected Products : mysql- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2019-4271
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243.... Read more
Affected Products : websphere_application_server- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39881
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client appl... Read more
Affected Products : gitlab- Published: Oct. 05, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-36181
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data... Read more
Affected Products : fortiportal- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-3011
Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafte... Read more
- Published: May. 08, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0341
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_i... Read more
Affected Products : pivotx- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4730
Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and conduct phishing attacks or obtain sensitive information via unknown vectors.... Read more
- Published: Nov. 11, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0407
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to... Read more
Affected Products : vm_virtualbox- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025