Latest CVE Feed
-
3.5
LOWCVE-2006-6822
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a m... Read more
Affected Products : eclassifieds- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1969
Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLink... Read more
Affected Products : cezanne- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-3728
Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HTML via the cat parameter in an admin_new_category action to admin.php.... Read more
Affected Products : kasseler-cms- Published: Mar. 13, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2006-1270
Multiple cross-site scripting (XSS) vulnerabilities in zones.php in Inprotect 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Description field. NOTE: the provenance of this information is unknown; the details a... Read more
Affected Products : inprotect- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2017-1353
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.... Read more
Affected Products : atlas_ediscovery_process_management- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2023-0969
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.... Read more
Affected Products : z\/ip_gateway_sdk- Published: Jun. 21, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-30950
A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.... Read more
Affected Products : fudforum- Published: Apr. 17, 2024
- Modified: Jun. 10, 2025
-
3.5
LOWCVE-2021-2159
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-44918
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : seacms- Published: Aug. 30, 2024
- Modified: Mar. 28, 2025
-
3.5
LOWCVE-2024-6620
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side reques... Read more
Affected Products :- Published: Jul. 29, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2025-37108
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2023-29066
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-18463
Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.... Read more
Affected Products : aikcms- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-3032
Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3147
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.... Read more
Affected Products : splunk- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3979
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated u... Read more
- Published: Jul. 25, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2729
Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects ta... Read more
Affected Products : ektron_content_management_system- Published: Apr. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-1988
The Phone Messages feature in Cybozu Garoon 2.0.0 through 3.7 SP2 allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.... Read more
Affected Products : garoon- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4139
Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php.... Read more
Affected Products : wp_smiley- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-2377
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 4.1.0 allows remote authenticated users to affect confidentiality via unknown vectors related to My Services.... Read more
Affected Products : financial_services_software- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025