Latest CVE Feed
-
2.6
LOWCVE-2011-5256
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.... Read more
Affected Products : limesurvey- EPSS Score: %0.26
- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1842
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.... Read more
Affected Products : shoutbook- EPSS Score: %0.53
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-47784
Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
2.6
LOWCVE-2006-2366
ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files via an arbitrary destination file name in an OBEX File Tr... Read more
Affected Products : openobex- EPSS Score: %0.39
- Published: May. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2265
Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance of this information is unknown; the details are obtained... Read more
Affected Products : calendar_manager_pro- EPSS Score: %3.88
- Published: May. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1975
Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.... Read more
Affected Products : php-gastebuch- EPSS Score: %0.40
- Published: Apr. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1969
Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web s... Read more
Affected Products : portal_pack- EPSS Score: %0.53
- Published: Apr. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1967
Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.... Read more
- EPSS Score: %0.53
- Published: Apr. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-28864
SecureProps is a PHP library designed to simplify the encryption and decryption of property data in objects. A vulnerability in SecureProps version 1.2.0 and 1.2.1 involves a regex failing to detect tags during decryption of encrypted data. This occurs wh... Read more
Affected Products :- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2024-7998
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.... Read more
- Published: Aug. 21, 2024
- Modified: Jul. 02, 2025
-
2.6
LOWCVE-2006-2031
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
Affected Products : phpmyadmin- EPSS Score: %0.41
- Published: Apr. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0553
Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.... Read more
Affected Products : ipfilter- EPSS Score: %0.44
- Published: May. 26, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4726
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.... Read more
Affected Products : coldfusion- EPSS Score: %2.04
- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4210
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these deta... Read more
Affected Products : phpay- EPSS Score: %5.90
- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4259
Cross-site scripting (XSS) vulnerability in index.php in Fotopholder 1.8 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this might be resultant from a directory traversal vulnerability.... Read more
Affected Products : fotopholder- EPSS Score: %0.40
- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4080
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.... Read more
Affected Products : deluxebb- EPSS Score: %0.33
- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4739
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php.... Read more
Affected Products : jetbox_cms- EPSS Score: %0.33
- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2025-55285
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly... Read more
Affected Products : backstage- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
-
2.6
LOWCVE-2006-1806
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.... Read more
Affected Products : musicbox- EPSS Score: %0.53
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3253
Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the i... Read more
Affected Products : vbulletin- EPSS Score: %6.15
- Published: Jun. 28, 2006
- Modified: Apr. 03, 2025