Latest CVE Feed
-
3.5
LOWCVE-2006-4360
Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal_e-commerce_module- Published: Aug. 27, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2012-2360
Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a p... Read more
Affected Products : moodle- Published: Jul. 21, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-37109
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2006-6548
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/re... Read more
Affected Products : webhost_manager- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-0544
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core, a... Read more
Affected Products : financial_services_software- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4586
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permissio... Read more
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-1733
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect confidentiality via unknown vectors related to CM.... Read more
Affected Products : peoplesoft_products- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-1281
Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be ... Read more
Affected Products : mybulletinboard- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-1969
Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLink... Read more
Affected Products : cezanne- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6822
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a m... Read more
Affected Products : eclassifieds- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2012-2309
Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-1270
Multiple cross-site scripting (XSS) vulnerabilities in zones.php in Inprotect 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Description field. NOTE: the provenance of this information is unknown; the details a... Read more
Affected Products : inprotect- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2015-4132
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-12769
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ... Read more
Affected Products : simple_banner- Published: Mar. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2015-4372
Cross-site scripting (XSS) vulnerability in the Image Title module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : image_title- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-3613
Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default. ... Read more
Affected Products : mattermost_server- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-30565
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.... Read more
Affected Products : guardrails_cqi_reporter- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-10554
The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit... Read more
Affected Products : wp-advanced-search- Published: Mar. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-34521
A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the file permissions of the privileged system user running the ap... Read more
Affected Products :- Published: Feb. 12, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2022-3343
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to infla... Read more
- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025