Latest CVE Feed
-
3.5
LOWCVE-2008-2768
Cross-site scripting (XSS) vulnerability in admin/search.asp in Xigla Poll Manager XE allows remote authenticated users with administrator role privileges to inject arbitrary web script or HTML via unspecified vectors ("all fields").... Read more
Affected Products : absolute_poll_manager_xe- Published: Jun. 18, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-10558
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: Mar. 24, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2006-0657
Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before bei... Read more
Affected Products : php_event_calendar- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-3741
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTM... Read more
Affected Products : drupal- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-6505
Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root, which makes it easier for attackers to avoid detection and can make it more ... Read more
Affected Products : solaris- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-3268
Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing ... Read more
- Published: Feb. 01, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-5061
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter t... Read more
Affected Products : manageengine_assetexplorer- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-33229
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML. ... Read more
Affected Products : solarwinds_platform- Published: Jul. 26, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-4992
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : sterling_b2b_integrator- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-8919
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal ... Read more
Affected Products : gerrit- Published: Dec. 10, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-1807
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.... Read more
- Published: Oct. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5070
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obta... Read more
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2015-2559
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.... Read more
- Published: Mar. 25, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6353
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through 5.4.1.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuu28922.... Read more
Affected Products : firesight_system_software- Published: Oct. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4924
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect integrity via vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6363
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuw88396.... Read more
Affected Products : firesight_system_software- Published: Nov. 12, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6535
Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).... Read more
Affected Products : youtube_embed- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-8105
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.... Read more
- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4913
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.... Read more
Affected Products : ubuntu_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus enterprise_linux_server_tus mysql +5 more products- Published: Oct. 22, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4864
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.... Read more
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025