Latest CVE Feed
-
3.5
LOWCVE-2016-6001
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.... Read more
Affected Products : forms_experience_builder- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-5509
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Difficult to exploit vulnerability allows l... Read more
Affected Products : flexcube_investor_servicing- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2021-25014
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Store... Read more
Affected Products : ibtana- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39220
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images... Read more
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-18463
Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.... Read more
Affected Products : aikcms- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2025-37108
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2013-3069
Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1) UserName or (2) Password to the NAS User Setup page, (3) deviceName to USB_a... Read more
- Published: Apr. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8748
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.... Read more
Affected Products : doubleclick_for_publishers- Published: Oct. 13, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-2065
Cross-site scripting (XSS) vulnerability in the Language Icons module 6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with administer languages permissions to inject arbitrary web script or HTML via unspecifi... Read more
- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2008-3782
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field und... Read more
Affected Products : acg_ptp- Published: Aug. 26, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-4372
Cross-site scripting (XSS) vulnerability in the Image Title module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : image_title- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4132
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8913
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vu... Read more
Affected Products : business_process_manager- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5365
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "What's going on?" profile field.... Read more
Affected Products : zurmo_crm- Published: Jul. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3989
IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the ... Read more
Affected Products : security_appscan- Published: Oct. 25, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-5621
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modul... Read more
- Published: Oct. 22, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-2289
Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when cre... Read more
Affected Products : serendipity- Published: Mar. 23, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2197
Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.... Read more
Affected Products : entity_api- Published: Mar. 03, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-3591
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editin... Read more
Affected Products : phpmyadmin- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-0944
The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
Affected Products : avamar- Published: May. 03, 2013
- Modified: Apr. 11, 2025