Latest CVE Feed
-
2.6
LOWCVE-2006-1899
Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) website parameters.... Read more
Affected Products : neuron_blog- EPSS Score: %0.53
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-3737
Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.p... Read more
Affected Products : storesprite- EPSS Score: %0.62
- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-1906
Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : phplister- EPSS Score: %6.99
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-0933
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_a... Read more
Affected Products : acidcat_cms- EPSS Score: %7.79
- Published: Jan. 29, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-2988
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CV... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.36
- Published: Aug. 27, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-0046
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML via the title att... Read more
Affected Products : ember.js- EPSS Score: %0.52
- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2011-5256
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.... Read more
Affected Products : limesurvey- EPSS Score: %0.26
- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4909
Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly h... Read more
Affected Products : guard_ddos_mitigation_appliance- EPSS Score: %0.50
- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1907
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".... Read more
Affected Products : personal_firewall- EPSS Score: %8.54
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4374
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.... Read more
Affected Products : irfanview- EPSS Score: %3.96
- Published: Aug. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0870
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.... Read more
Affected Products : internet_explorer- EPSS Score: %9.12
- Published: Oct. 01, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-5514
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary web script or HTML via a destination field label.... Read more
Affected Products : migrate- EPSS Score: %0.36
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-2979
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum... Read more
Affected Products : shop- EPSS Score: %0.61
- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0861
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.... Read more
Affected Products : internet_information_server site_server site_server_commerce commercial_internet_system- EPSS Score: %5.46
- Published: Aug. 11, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1753
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and f... Read more
- EPSS Score: %0.87
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0827
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.... Read more
- EPSS Score: %0.88
- Published: Nov. 01, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4066
The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico... Read more
Affected Products : windows_xp- EPSS Score: %22.26
- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-2333
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : lazyest-gallery- EPSS Score: %0.38
- Published: Apr. 11, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2008-5211
Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attackers to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.... Read more
Affected Products : sphider- EPSS Score: %3.79
- Published: Nov. 24, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-3731
Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted attackers to cause a denial of service (crash) via a form with a multipart/form-data encoding and a user-uploaded file. NOTE: a third party has claimed that this issue might be related to th... Read more
Affected Products : firefox- EPSS Score: %0.66
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025