Latest CVE Feed
-
3.5
LOWCVE-2020-2694
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.18 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multipl... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2011-0728
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.... Read more
Affected Products : loggerhead- Published: Mar. 29, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0606
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.... Read more
Affected Products : osticket- Published: Feb. 11, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-13261
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.... Read more
Affected Products : dam- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2010-3512
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0u8 allows remote authenticated users to affect confidentiality, related to DAV (WebDAV).... Read more
Affected Products : sun_products_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2023-3906
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.... Read more
Affected Products : gitlab- Published: Sep. 29, 2023
- Modified: May. 05, 2025
-
3.5
LOWCVE-2010-4624
MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created.... Read more
Affected Products : mybb- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-0700
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3)... Read more
Affected Products : wordpress- Published: Mar. 14, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0697
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML vi... Read more
- Published: Feb. 23, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0081
Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2381.... Read more
Affected Products : fusion_middleware- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4760
Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-15103
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly acc... Read more
- Published: Jul. 27, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-23056
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.... Read more
- Published: Jun. 22, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-2334
Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Creat... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-2086
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.... Read more
Affected Products : panopoly_magic- Published: Feb. 26, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1617
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : data_loss_prevention_endpoint- Published: Feb. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-9499
Cross-site scripting (XSS) vulnerability in the Godwin's Law module before 7.x-1.1 for Drupal, when using the dblog module, allows remote authenticated users to inject arbitrary web script or HTML via a Watchdog message.... Read more
Affected Products : godwin\'s_law- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6148
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sen... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2273
Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to inject arbitrary web script o... Read more
Affected Products : moodle- Published: Jun. 01, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1516
Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : realpresence_cloudaxis_suite- Published: Sep. 03, 2015
- Modified: Apr. 12, 2025