Latest CVE Feed
-
3.5
LOWCVE-2013-3503
The Profile Importer feature in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an enti... Read more
Affected Products : groundwork_monitor- Published: May. 08, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3740
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.... Read more
Affected Products : spiceworks- Published: Sep. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2006-0172
Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is publ... Read more
Affected Products : enterprise_collaboration- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2015-0127
IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users ... Read more
Affected Products : leads- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7490
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.... Read more
Affected Products : infosphere_information_server- Published: Mar. 03, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2017-1353
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.... Read more
Affected Products : atlas_ediscovery_process_management- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2023-0969
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.... Read more
Affected Products : z\/ip_gateway_sdk- Published: Jun. 21, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2020-14732
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : retail_customer_management_and_segmentation_foundation- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2019-19090
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.... Read more
Affected Products : esoms- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-10545
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered... Read more
Affected Products : nextgen_gallery- Published: Feb. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2020-5301
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP ... Read more
Affected Products : simplesamlphp- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-5460
IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and read communication logs associated with unrelated records... Read more
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2010-0909
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-5404
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other p... Read more
- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6237
The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.... Read more
- Published: Dec. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-2702
Cross-site scripting (XSS) vulnerability in the GroupSpace application in BEA WebLogic Portal 9.2 GA allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the rich text editor.... Read more
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-4542
Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data stor... Read more
Affected Products : unity- Published: Oct. 13, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-2844
Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote authenticated administrators to inject arbitrary web script or HTML via the new parameter in the SysUser module to admin.... Read more
Affected Products : secure_messaging_secure_gateway- Published: Apr. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-5420
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.... Read more
Affected Products : security_access_manager_for_enterprise_single_sign-on- Published: Dec. 23, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-2544
Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site ... Read more
Affected Products : telepresence_system_1000_mxp telepresence_system_1700_mxp telepresence_mxp_software- Published: Sep. 23, 2011
- Modified: Apr. 11, 2025