Latest CVE Feed
-
3.5
LOWCVE-2008-1969
Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLink... Read more
Affected Products : cezanne- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6548
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/re... Read more
Affected Products : webhost_manager- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-0544
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core, a... Read more
Affected Products : financial_services_software- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-6822
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a m... Read more
Affected Products : eclassifieds- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-4358
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Ubercart Discount Coupons module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via ve... Read more
Affected Products : ubercart_discount_coupons- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2005-4189
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith H3 before 2.0.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Calendar name field when creating calendars, (2) event title field when deleting eve... Read more
Affected Products : kronolith_h3- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2014-6525
Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Tem... Read more
Affected Products : e-business_suite- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6487
Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect integrity via unknown vectors related to End User Self Service.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4756
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to hijack sessions via unspecified vectors.... Read more
Affected Products : rational_license_key_server- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-2150
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to shared files.... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4770
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via... Read more
Affected Products : websphere_application_server- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2003-1570
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations ... Read more
Affected Products : tivoli_storage_manager- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-10554
The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit... Read more
Affected Products : wp-advanced-search- Published: Mar. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-42955
Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful exploit could lead to reduced performan... Read more
Affected Products : cloud_connector- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2007-5621
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modul... Read more
- Published: Oct. 22, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2011-3591
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted row that triggers an improperly constructed confirmation message after inline-editin... Read more
Affected Products : phpmyadmin- Published: Dec. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-12769
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ... Read more
Affected Products : simple_banner- Published: Mar. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2006-0172
Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is publ... Read more
Affected Products : enterprise_collaboration- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2015-2827
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5150
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authenticated users to inject arbitrary web script or HTML via the (1) query parameter in the run_query_editor_query module to CustomReportHandle... Read more
Affected Products : manageengine_supportcenter_plus- Published: Jun. 30, 2015
- Modified: Apr. 12, 2025