Latest CVE Feed
-
3.5
LOWCVE-2024-13261
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.... Read more
Affected Products : dam- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2011-3592
Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) c... Read more
Affected Products : phpmyadmin- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-0826
Unspecified vulnerability in Oracle PeopleSoft Enterprise 8.8 Bundle #13, 8.9 Bundle #7, 9.0 Bundle #7, and 9.1 Bundle #4 allows remote authenticated users to affect integrity via unknown vectors related to Application Portal.... Read more
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-2282
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50.20 and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors.... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-0795
Unspecified vulnerability in the Single Sign On component in Oracle Fusion Middleware 10.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Administration and Monitoring.... Read more
Affected Products : fusion_middleware- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-11526
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.... Read more
- Published: May. 15, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2011-1491
The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to th... Read more
- Published: Apr. 08, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-1503
The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.... Read more
- Published: May. 07, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-0810
Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.... Read more
Affected Products : skate_board- Published: Feb. 21, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2019-2547
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privil... Read more
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-2899
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions that are affected are 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attack... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2008-3741
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTM... Read more
Affected Products : drupal- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3301
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow... Read more
Affected Products : bilboblog- Published: Jul. 25, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-4628
The firewall module on the Huawei Quidway Service Process Unit (SPU) board S7700, S9300, and S9700 on Huawei Campus Switch devices allows remote authenticated users to obtain sensitive information from the high-priority security zone by leveraging access ... Read more
- Published: Jun. 20, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6374
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : build_failure_analyzer- Published: Nov. 25, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3034
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.... Read more
Affected Products : infosphere_information_server- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3031
A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x before 6.3.0.56, 6.5.x before 6.5.0.12, and 7.0.x before 7.0.0.4 allows remote authenticated users to cause a denial of service (uninitialized-memory acces... Read more
Affected Products : soliddb- Published: Sep. 09, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3836
Unspecified vulnerability in the Oracle Web Cache component in Oracle Fusion Middleware 11.1.1.6 and 11.1.1.7 allows remote authenticated users to affect confidentiality via vectors related to ESI/Partial Page Caching.... Read more
Affected Products : fusion_middleware- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-3720
Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter.... Read more
- Published: May. 31, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-5000
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. ... Read more
Affected Products : openssh- Published: Apr. 05, 2012
- Modified: Apr. 11, 2025