Latest CVE Feed
-
3.5
LOWCVE-2008-1330
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the ... Read more
Affected Products : groupwise- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-0692
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili... Read more
Affected Products : simple_video_management_system- Published: Feb. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1623
The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : gdpr_cookie_compliance- Published: Mar. 16, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1131
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.... Read more
Affected Products : drupal- Published: Mar. 04, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-13121
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform ... Read more
Affected Products : profilepress- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2021-39164
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerabil... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-3624
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to app... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-39163
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limit... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-2000
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having SYS Account privilege with network ac... Read more
Affected Products : database_server- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2018-16968
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.... Read more
Affected Products : sharefile_storagezones_controller- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-0540
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.... Read more
Affected Products : websphere_application_server- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-3029
Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers ... Read more
Affected Products : securityexpressions_audit_and_compliance_server- Published: Oct. 15, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-0597
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecifie... Read more
Affected Products : websphere_application_server- Published: Aug. 21, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3093
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.... Read more
Affected Products : drupal- Published: Sep. 21, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-6145
Cross-site scripting (XSS) vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : typo3- Published: Jul. 01, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3371
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via ... Read more
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-1570
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than... Read more
- Published: May. 07, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-4770
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via... Read more
Affected Products : websphere_application_server- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4756
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to hijack sessions via unspecified vectors.... Read more
Affected Products : rational_license_key_server- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-2237
Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 10.1.3.5.0 and 10.1.3.5.1 allows remote authenticated users to affect integrity, related to WSM Console, a different vulnerability than CVE-2011-3523.... Read more
Affected Products : fusion_middleware- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025