Latest CVE Feed
-
3.5
LOWCVE-2008-3741
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTM... Read more
Affected Products : drupal- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-6505
Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root, which makes it easier for attackers to avoid detection and can make it more ... Read more
Affected Products : solaris- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-0077
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote authenticated users to affect integrity, related to WLS-Console.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-2632
Cross-site scripting (XSS) vulnerability in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via file descriptions.... Read more
Affected Products : bytehoard- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-3874
Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==> Value pairs). NOTE: some of these details... Read more
Affected Products : vanilla- Published: Aug. 29, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3262
Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.... Read more
Affected Products : tivoli_identity_manager- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-0275
Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 1... Read more
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-51385
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.... Read more
- Published: Jul. 31, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
3.5
LOWCVE-2025-53862
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.... Read more
Affected Products : ansible_automation_platform- Published: Jul. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2024-13314
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_htm... Read more
Affected Products : carousel\,_slider\,_gallery_by_wp_carousel- Published: Feb. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1623
The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : gdpr_cookie_compliance- Published: Mar. 16, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-12683
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : smart_maintenance_mode- Published: Mar. 26, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13123
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for exa... Read more
Affected Products : advanced_form_integration- Published: Mar. 25, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13122
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for exa... Read more
Affected Products : advanced_form_integration- Published: Mar. 25, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1452
The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ... Read more
Affected Products : favorites- Published: Mar. 25, 2025
- Modified: May. 06, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-10558
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: Mar. 24, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2008-1627
CDS Invenio 0.92.1 and earlier allows remote authenticated users to delete email notification alerts of arbitrary users via a modified internal UID.... Read more
Affected Products : invenio- Published: Apr. 02, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1775
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details a... Read more
- Published: Apr. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-12173
The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : master_slider- Published: Feb. 19, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-57611
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery