Latest CVE Feed
-
3.5
LOWCVE-2020-12251
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, ob... Read more
Affected Products : gigavue- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-8897
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 b... Read more
- Published: Dec. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-1949
Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-201... Read more
Affected Products : plone- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2018-3184
Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: IQR - Foundation Services). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to ... Read more
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-4608
Cross-site scripting (XSS) vulnerability in the BE User Log (beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : be_user_log- Published: Jun. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5491
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.... Read more
Affected Products : dynamic_display_block- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2007-5949
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.... Read more
Affected Products : tivoli_service_desk- Published: Nov. 14, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2007-4717
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUse... Read more
Affected Products : claroline- Published: Sep. 05, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2022-0279
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users... Read more
Affected Products : anycomment- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-2406
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2009-2919
Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.... Read more
Affected Products : orca- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2024-52507
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextclou... Read more
Affected Products : notes- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
3.5
LOWCVE-2009-3206
Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated users, with "administer imagecache" permissions, to inject arbitrary web script ... Read more
- Published: Sep. 16, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-9362
Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web scri... Read more
Affected Products : meta_tags_quick- Published: Dec. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-2361
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via... Read more
Affected Products : moodle- Published: Jul. 21, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-7292
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-... Read more
Affected Products : identikey_authentication_server- Published: Jan. 13, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-6494
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mango_automation- Published: Oct. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2023-4654
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.... Read more
- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-3376
Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : quizzler- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3384
Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : commerce_balanced_payments- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025