Latest CVE Feed
-
2.6
LOWCVE-2011-2477
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onlo... Read more
Affected Products : icinga- EPSS Score: %0.26
- Published: Jun. 14, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-1279
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin component, (2) com_search component when "Gather Search Statistics"... Read more
Affected Products : joomla- EPSS Score: %0.01
- Published: Apr. 09, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2012-3587
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-midd... Read more
- EPSS Score: %0.15
- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1783
Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.... Read more
Affected Products : cms- EPSS Score: %0.35
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-4954
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary we... Read more
- EPSS Score: %4.92
- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-0513
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity, related to REST Services.... Read more
Affected Products : e-business_suite- EPSS Score: %0.36
- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-4549
The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlide... Read more
Affected Products : imageshack_toolbar- EPSS Score: %6.72
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4355
Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal_easylinks_module- EPSS Score: %0.41
- Published: Aug. 27, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1683
Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.... Read more
Affected Products : word- EPSS Score: %15.13
- Published: May. 20, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-4783
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner paramet... Read more
Affected Products : easy_banner_free- EPSS Score: %4.38
- Published: Apr. 07, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4369
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via an absolute pathname in the phpbb_root_path parameter.... Read more
Affected Products : integramod_portal- EPSS Score: %8.37
- Published: Aug. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2003-1581
The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequenc... Read more
Affected Products : http_server- EPSS Score: %0.90
- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-1999-0468
Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.... Read more
Affected Products : internet_explorer- EPSS Score: %5.21
- Published: Apr. 09, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0733
Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the resear... Read more
Affected Products : wordpress- EPSS Score: %0.61
- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-3266
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE ... Read more
Affected Products : wireshark- EPSS Score: %1.02
- Published: Aug. 24, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-4583
Opera before 11.00, when Opera Turbo is enabled, does not display a page's security indication, which makes it easier for remote attackers to spoof trusted content via a crafted web site.... Read more
Affected Products : opera_browser- EPSS Score: %0.33
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2024-45712
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.... Read more
Affected Products : serv-u- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
-
2.6
LOWCVE-2012-5868
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.... Read more
Affected Products : wordpress- EPSS Score: %0.72
- Published: Dec. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-6618
The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of s... Read more
Affected Products : ffmpeg- EPSS Score: %1.05
- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-4584
Opera before 11.00, when Opera Turbo is used, does not properly present information about problematic X.509 certificates on https web sites, which might make it easier for remote attackers to spoof trusted content via a crafted web site.... Read more
Affected Products : opera_browser- EPSS Score: %0.18
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025