Latest CVE Feed
-
3.5
LOWCVE-2014-0894
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2291
Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote a... Read more
Affected Products : ive_os- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0884
Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : lotus_protector_for_mail_security- Published: Mar. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0874
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter.... Read more
Affected Products : content_navigator- Published: Feb. 28, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0970
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links ... Read more
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6745
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecif... Read more
Affected Products : security_access_manager_for_enterprise_single_sign-on- Published: Dec. 22, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0910
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_portal- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6729
Cross-site scripting (XSS) vulnerability in IBM QuickFile 1.0.0.0 before iFix 4 and 1.1.0.1 before iFix 3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : quickfile- Published: Mar. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0915
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; ... Read more
- Published: Jul. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-28838
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.... Read more
Affected Products : opencart- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-6721
Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.... Read more
Affected Products : websphere_service_registry_and_repository- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-6741
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Servi... Read more
- Published: May. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-37314
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-8105
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.... Read more
- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6363
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuw88396.... Read more
Affected Products : firesight_system_software- Published: Nov. 12, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6336
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecifi... Read more
Affected Products : exchange_server- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0379
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.... Read more
Affected Products : websphere_mq- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2020-8919
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal ... Read more
Affected Products : gerrit- Published: Dec. 10, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-4962
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before ... Read more
- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5061
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter t... Read more
Affected Products : manageengine_assetexplorer- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025