Latest CVE Feed
-
2.6
LOWCVE-2009-2492
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.... Read more
- EPSS Score: %0.36
- Published: Jul. 17, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2013-4504
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.... Read more
- EPSS Score: %0.28
- Published: May. 13, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-1673
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.... Read more
Affected Products : vbug_tracker- EPSS Score: %0.68
- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1120
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in ... Read more
Affected Products : dcp-portal- EPSS Score: %1.45
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-1614
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form... Read more
Affected Products : leap- EPSS Score: %0.23
- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2015-6921
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : zendesk_feedback_tab- EPSS Score: %0.32
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-2051
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix ... Read more
Affected Products : enterprise_linux- EPSS Score: %0.34
- Published: Jul. 09, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-0820
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbo... Read more
- EPSS Score: %0.30
- Published: Feb. 25, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-2625
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.... Read more
- EPSS Score: %1.86
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2024-30252
Livemarks is a browser extension that provides RSS feed bookmark folders. Versions of Livemarks prior to 3.7 are vulnerable to cross-site request forgery. A malicious website may be able to coerce the extension to send an authenticated GET request to an a... Read more
Affected Products :- Published: Apr. 04, 2024
- Modified: Feb. 27, 2025
-
2.6
LOWCVE-2006-2648
Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.... Read more
Affected Products : aspbb- EPSS Score: %7.01
- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0716
WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.... Read more
Affected Products : mdaemon- EPSS Score: %0.42
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0888
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.... Read more
Affected Products : invision_power_board- EPSS Score: %6.56
- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0797
NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.... Read more
Affected Products : sunos- EPSS Score: %0.55
- Published: Jun. 29, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0538
CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections.... Read more
Affected Products : ironmail- EPSS Score: %1.12
- Published: Feb. 04, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0768
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.... Read more
- EPSS Score: %16.32
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1226
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.... Read more
Affected Products : communicator- EPSS Score: %0.50
- Published: Oct. 28, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-41985
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session ... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
2.6
LOWCVE-2006-3071
Cross-site scripting (XSS) vulnerability in index.php in MP3 Search/Archive 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter, as used by the "search box", and (2) res parameter.... Read more
Affected Products : mp3_search_archive- EPSS Score: %0.53
- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0406
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Su... Read more
Affected Products : communicator- EPSS Score: %0.74
- Published: May. 10, 2000
- Modified: Apr. 03, 2025