Latest CVE Feed
-
3.5
LOWCVE-2023-24375
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Disc... Read more
Affected Products : wordpress_social_login_and_register_\(discord\,_google\,_twitter\,_linkedin\)- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
3.5
LOWCVE-2022-23072
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and c... Read more
Affected Products : recipes- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-23058
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.... Read more
- Published: Jun. 22, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-2909
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-3511
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge req... Read more
Affected Products : gitlab- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-3254
Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflo... Read more
Affected Products : enterprise_document_manager- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-1467
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, Cal... Read more
Affected Products : unified_meetingplace call_manager vpn_client network_analysis_module acs_solution_engine ciscoworks ip_communicator meetingplace security_device_manager unified_meetingplace_express +8 more products- Published: Mar. 16, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-1828
Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the QUERY_STRING corresponding to drop downs or (2) various forms.... Read more
Affected Products : webapp- Published: Apr. 03, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-49098
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.... Read more
Affected Products : discourse_reactions- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-0519
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.... Read more
Affected Products : u2u_instant_messenger- Published: Jan. 26, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-0437
Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie... Read more
Affected Products : cache_database- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-1947
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbi... Read more
Affected Products : firebug- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-4340
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.... Read more
Affected Products : wordpress- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3810
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA Transactions.... Read more
Affected Products : mysql- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-4986
Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name ... Read more
Affected Products : phpmyadmin- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3742
Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name tha... Read more
Affected Products : phpmyadmin- Published: Jul. 04, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-9475
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated users to inject arbitrary web script or HTML via a wikitext message.... Read more
Affected Products : mediawiki- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2006-2539
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the clea... Read more
Affected Products : easerver- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2014-2430
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema.... Read more
- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-41946
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid crede... Read more
Affected Products : frugal_testing- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024