Latest CVE Feed
-
3.5
LOWCVE-2011-2303
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Attachments / File Upload.... Read more
Affected Products : e-business_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-2282
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50.20 and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors.... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-16218
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful e... Read more
- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2007-3559
Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FU... Read more
- Published: Jul. 04, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4427
Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote authenticated users to modify data on a server, related to encoding of cert... Read more
Affected Products : cache_database- Published: Aug. 20, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4413
Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote authenticated users to inject arbitrary PHP code into an unspecified file via a new_entry value in the do parameter.... Read more
Affected Products : deskpro- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-3254
Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflo... Read more
Affected Products : enterprise_document_manager- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-55455
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.... Read more
Affected Products :- Published: Aug. 22, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2007-4523
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.p... Read more
Affected Products : ripe_website_manager- Published: Aug. 25, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-5414
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authen... Read more
Affected Products : websphere_application_server- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5418
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a... Read more
Affected Products : websphere_application_server- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5572
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.... Read more
Affected Products : zabbix- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-4927
axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.... Read more
Affected Products : 207w_network_camera- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-1511
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-2004
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.s... Read more
Affected Products : fedora curl ontap_select_deploy_administration_utility macos h300s_firmware h500s_firmware h700s_firmware h410s_firmware bootstrap_os hci_compute_node +5 more products- Published: Mar. 27, 2024
- Modified: Jul. 30, 2025
-
3.5
LOWCVE-2012-1987
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory... Read more
- Published: May. 29, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5571
OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for th... Read more
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-4459
Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a group membership.... Read more
- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-3830
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.... Read more
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3903
Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, whe... Read more
- Published: Sep. 04, 2008
- Modified: Apr. 09, 2025