Latest CVE Feed
-
3.5
LOWCVE-2016-4027
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10. App Suite frontend offers to control whether a user wants to store cookies that exceed the session duration. This functionality is useful when logging in from clients with reduced pr... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 15, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4938
Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the banner message.... Read more
Affected Products : pattern_insight- Published: Nov. 18, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-55523
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2021-33031
In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without access to user management in order to, after successful exploitation, gain access to a victim's account. A user without the user-manageme... Read more
Affected Products : labcup- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-5500
Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : navigate- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-3097
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.... Read more
Affected Products : tinytax_taxonomy_block_module- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3993
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-2406
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-8318
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML ... Read more
Affected Products : webform- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-5833
Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web script or HTML via (1) user info (account details) or (2) a post.... Read more
Affected Products : bosmarket_business_directory_system- Published: Nov. 05, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-5491
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.... Read more
Affected Products : dynamic_display_block- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4374
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a componen... Read more
Affected Products : webform- Published: Jun. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-1762
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-3111.... Read more
Affected Products : peoplesoft_products- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-9461
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_download action to wp-admin/admin-ajax.php.... Read more
Affected Products : cart66_lite- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-1738
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."... Read more
- Published: May. 20, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2009-2079
Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use ... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2011-1949
Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-201... Read more
Affected Products : plone- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-2698
Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOT... Read more
Affected Products : community_software- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-5949
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.... Read more
Affected Products : tivoli_service_desk- Published: Nov. 14, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2013-5871
Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vuln... Read more
Affected Products : supply_chain_products_suite- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025