Latest CVE Feed
-
3.5
LOWCVE-2013-5764
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect availability via unknown vectors.... Read more
Affected Products : database_server- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3371
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via ... Read more
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5378
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging incorrect IBM Connections integration.... Read more
Affected Products : websphere_portal- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-43446
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * (... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2024-2220
The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : call_\/_chat_\/_contact_button- Published: May. 23, 2024
- Modified: May. 15, 2025
-
3.5
LOWCVE-2024-3920
The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : flattr- Published: May. 23, 2024
- Modified: May. 21, 2025
-
3.5
LOWCVE-2008-6170
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.... Read more
Affected Products : drupal- Published: Feb. 19, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-0093
Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Disco... Read more
- Published: Mar. 11, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-2641
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4861
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.... Read more
Affected Products : ubuntu_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_tus mysql +5 more products- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-3797
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mac_os_x_server- Published: Nov. 16, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-56082
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.... Read more
Affected Products :- Published: Dec. 15, 2024
- Modified: Dec. 16, 2024
-
3.5
LOWCVE-2020-26220
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version... Read more
Affected Products : touchbase.ai- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-19090
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.... Read more
Affected Products : esoms- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-5301
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP ... Read more
Affected Products : simplesamlphp- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-6879
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request... Read more
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-14732
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2006-5453
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using t... Read more
Affected Products : bugzilla- Published: Oct. 23, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-23847
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing cr... Read more
Affected Products : synopsys_coverity- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
3.5
LOWCVE-2023-37541
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.... Read more
Affected Products : connections- Published: Jun. 25, 2024
- Modified: Feb. 26, 2025