Latest CVE Feed
-
3.5
LOWCVE-2015-0549
Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before 4.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : documentum_d2- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8909
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before CF05 allows remote authenticated users to inject arbit... Read more
Affected Products : websphere_portal- Published: Feb. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2018
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspec... Read more
- Published: Aug. 23, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4540
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 and 6.9.x before 6.9.1 P6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rsa_identity_management_and_governance- Published: Sep. 26, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3365
Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a Profile2 field in a provided block.... Read more
Affected Products : nodeauthor- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5892
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to... Read more
Affected Products : vm_virtualbox- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-9097
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.... Read more
Affected Products : manageengine_endpoint_central- Published: Feb. 05, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2024-37314
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-0412
Unspecified vulnerability in the PeopleSoft Enterprise SCM eProcurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Manage Requisition Status.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-6539
The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in reverse. The MAC address can be obtained by being in close proximity to the Bluetooth device, effectively exposing the device ID. The ID can... Read more
- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2016-0370
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.... Read more
Affected Products : forms_experience_builder- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2005-4190
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) L... Read more
Affected Products : horde_application_framework- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2016-0379
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.... Read more
Affected Products : websphere_mq- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0385
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensi... Read more
Affected Products : websphere_application_server- Published: Sep. 01, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0968
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows... Read more
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3034
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to inject arbitrar... Read more
Affected Products : emptoris_contract_management- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3050
IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors.... Read more
Affected Products : rational_team_concert- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3096
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : curam_social_program_management- Published: Jan. 10, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5402
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utili... Read more
Affected Products : maximo_asset_management maximo_for_life_sciences maximo_for_nuclear_power maximo_for_oil_and_gas maximo_for_transportation maximo_for_utilities smartcloud_control_desk change_and_configuration_management_database maximo_asset_management_essentials maximo_for_government +2 more products- Published: Dec. 18, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-2933
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocol... Read more
Affected Products : fedora debian_linux mysql mysql_connector\/j mysql_connectors mysql_connector\/python- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024