Latest CVE Feed
-
2.6
LOWCVE-2012-1792
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the... Read more
Affected Products : online_merchant- EPSS Score: %0.22
- Published: May. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-3562
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.... Read more
Affected Products : xerver- EPSS Score: %0.85
- Published: Oct. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-3063
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text par... Read more
Affected Products : myphp_guestbook- EPSS Score: %0.42
- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2913
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.... Read more
Affected Products : selectapix- EPSS Score: %0.74
- Published: Jun. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3305
Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau Webmail 2.7.10, and 2.7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) f_user parameter in index.php, the (2) pag parameter in messages.php, or the (3... Read more
Affected Products : uebimiau- EPSS Score: %0.53
- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3656
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 200607... Read more
Affected Products : powerpoint- EPSS Score: %65.97
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-1517
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Diagnostics.... Read more
Affected Products : e-business_suite- EPSS Score: %0.32
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-5451
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (a) admin.php, which are not properly handled when the admi... Read more
Affected Products : torrentflux- EPSS Score: %1.10
- Published: Oct. 23, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-0089
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.... Read more
Affected Products : internet_explorer- EPSS Score: %38.30
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4975
Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service.... Read more
Affected Products : messenger- EPSS Score: %0.32
- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOW- Published: Sep. 11, 2024
- Modified: Jul. 02, 2025
-
2.6
LOWCVE-2006-4071
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafte... Read more
- EPSS Score: %22.84
- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-4457
OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.... Read more
Affected Products : owasp-java-html-sanitizer- EPSS Score: %0.22
- Published: Nov. 17, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-5564
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in... Read more
Affected Products : simple_php_forum- EPSS Score: %0.28
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4011
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.... Read more
Affected Products : esupport- EPSS Score: %5.04
- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-28864
SecureProps is a PHP library designed to simplify the encryption and decryption of property data in objects. A vulnerability in SecureProps version 1.2.0 and 1.2.1 involves a regex failing to detect tags during decryption of encrypted data. This occurs wh... Read more
Affected Products :- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2006-2031
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
Affected Products : phpmyadmin- EPSS Score: %0.41
- Published: Apr. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2163
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.... Read more
Affected Products : pinnacle_cart- EPSS Score: %0.51
- Published: May. 04, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-1949
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts. ... Read more
- Published: Feb. 29, 2024
- Modified: Dec. 13, 2024
-
2.6
LOWCVE-2025-0251
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 25, 2025