Latest CVE Feed
-
3.5
LOWCVE-2014-3594
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host a... Read more
- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-1511
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-55455
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.... Read more
Affected Products : dootask- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2012-5096
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.... Read more
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2011-4459
Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a group membership.... Read more
- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-4927
axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.... Read more
Affected Products : 207w_network_camera- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2019-1010310
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tool... Read more
Affected Products : glpi- Published: Jul. 12, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-4762
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- Published: Sep. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3149
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect confidentiality, related to MySQL Client.... Read more
Affected Products : mysql- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-2381
Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server Privileges.... Read more
Affected Products : mysql- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-22445
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2025-1523
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1525
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2009-0481
Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers... Read more
Affected Products : bugzilla- Published: Feb. 09, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2010-3797
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mac_os_x_server- Published: Nov. 16, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2025-4227
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-new-features/new-features-released-in-gp-app/endpoint-traffic-policy-enforcement feature of the Pal... Read more
- Published: Jun. 13, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2012-3865
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the p... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-3167
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.... Read more
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2006-6775
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.... Read more
Affected Products : acftp- Published: Dec. 27, 2006
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-6821
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified... Read more
Affected Products : enews- Published: Dec. 29, 2006
- Modified: Apr. 09, 2025