Latest CVE Feed
-
3.5
LOWCVE-2010-2535
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.... Read more
Affected Products : joomla\!- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13124
The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : photo_gallery- Published: Mar. 24, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13125
The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : everest_forms- Published: Feb. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2010-2474
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.... Read more
- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4427
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.0, 10.1.3.4.1, and 11.1.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3303
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an enumeration value or (3) a ... Read more
Affected Products : mantisbt- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2697
Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are ... Read more
Affected Products : community_software- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4807
Race condition in IBM Web Content Manager (WCM) 7.0.0.1 before CF003 allows remote authenticated users to cause a denial of service (infinite recursive query) via unspecified vectors, related to a StackOverflowError exception.... Read more
Affected Products : web_content_manager- Published: May. 26, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2080
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : otrs- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4547
IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended a... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3737
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while usin... Read more
Affected Products : db2- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3266
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the i... Read more
Affected Products : bugtracker.net- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-0084
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2381
Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2010-0081.... Read more
Affected Products : fusion_middleware- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4355
Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.... Read more
Affected Products : dadabik- Published: Dec. 01, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-3779
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox... Read more
Affected Products : dovecot- Published: Oct. 06, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4425
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4322
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.... Read more
Affected Products : vibe_onprem- Published: Jan. 07, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2048
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 25, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2802
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.2 allows remote authenticated users to inject arbitrary web script or HTML via an HTML document with a .gif filename extension, related to inline attachments.... Read more
Affected Products : mantisbt- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025