Latest CVE Feed
-
2.6
LOWCVE-2006-1843
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : shoutbook- EPSS Score: %0.34
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2022-4270
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.... Read more
- EPSS Score: %0.11
- Published: Dec. 02, 2022
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2006-1224
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.... Read more
Affected Products : guppy- EPSS Score: %9.20
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1818
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: por... Read more
Affected Products : warforge.news- EPSS Score: %0.35
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3923
Cross-site scripting (XSS) vulnerability in add.php in Fire-Mouse Toplist 1.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the Seitenname parameter.... Read more
Affected Products : fire-mouse_toplist- EPSS Score: %0.68
- Published: Jul. 28, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2025-0252
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
2.6
LOWCVE-2006-2974
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b... Read more
Affected Products : email_server- EPSS Score: %0.49
- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3563
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : winged_gallery- EPSS Score: %0.42
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-0856
Heap-based buffer overflow in the MPV_frame_start function in libavcodec/mpegvideo.c in FFmpeg before 0.9.1, when the lowres option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted H263 media file. NOTE: ... Read more
Affected Products : ffmpeg- EPSS Score: %1.14
- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-3661
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party inf... Read more
Affected Products : cutenews- EPSS Score: %0.30
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-1247
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.... Read more
Affected Products : web_mart- EPSS Score: %0.30
- Published: May. 15, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-6527
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
- EPSS Score: %0.36
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-4249
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters... Read more
Affected Products : cutenews- EPSS Score: %3.42
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-0807
Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.... Read more
Affected Products : internet_explorer- EPSS Score: %9.16
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0518
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.... Read more
- EPSS Score: %2.19
- Published: Jun. 05, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-3574
Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) la... Read more
- EPSS Score: %1.48
- Published: Aug. 10, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-0329
Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.... Read more
Affected Products : zipgenius- EPSS Score: %0.85
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-5893
Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action.... Read more
Affected Products : click\&email- EPSS Score: %1.35
- Published: Jan. 12, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-3712
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to mambots/editors/mostlyce/jscripts/tiny_mce/filemanage... Read more
Affected Products : mambo- EPSS Score: %4.01
- Published: Aug. 19, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-1615
Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.... Read more
Affected Products : opera_browser- EPSS Score: %1.57
- Published: Oct. 18, 2004
- Modified: Apr. 03, 2025