Latest CVE Feed
-
3.5
LOWCVE-2024-6620
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side reques... Read more
Affected Products :- Published: Jul. 29, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-32236
An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.... Read more
Affected Products : cmseasy- Published: Apr. 25, 2024
- Modified: Apr. 14, 2025
-
3.5
LOWCVE-2024-3920
The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : flattr- Published: May. 23, 2024
- Modified: May. 21, 2025
-
3.5
LOWCVE-2020-26220
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version... Read more
Affected Products : touchbase.ai- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-5301
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP ... Read more
Affected Products : simplesamlphp- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-6879
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request... Read more
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-14732
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2009-4237
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the req parameter to login.php, and allow remote authenticated users to inject arbitrary web script or HTML ... Read more
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-22329
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.... Read more
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2008-2603
Unspecified vulnerability in the Resource Manager component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6, and Database Control in Enterprise Manager, has unknown impact and remote authenticated attack vectors. NOTE: the previous information was obt... Read more
Affected Products : enterprise_manager- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-3029
Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers ... Read more
Affected Products : securityexpressions_audit_and_compliance_server- Published: Oct. 15, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-4370
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, ... Read more
Affected Products : drupal- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-1828
Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the QUERY_STRING corresponding to drop downs or (2) various forms.... Read more
Affected Products : webapp- Published: Apr. 03, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-2909
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update.... Read more
- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-0437
Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie... Read more
Affected Products : cache_database- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2023-49098
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.... Read more
Affected Products : discourse_reactions- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-1732
Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknow... Read more
Affected Products : wordpress- Published: Mar. 28, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-0519
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.... Read more
Affected Products : u2u_instant_messenger- Published: Jan. 26, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-43446
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * (... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2024-56082
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.... Read more
Affected Products :- Published: Dec. 15, 2024
- Modified: Dec. 16, 2024