Latest CVE Feed
-
3.5
LOWCVE-2014-3147
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.... Read more
Affected Products : splunk- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-4473
The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nodes via a direct request.... Read more
- Published: Nov. 30, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-2377
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 4.1.0 allows remote authenticated users to affect confidentiality via unknown vectors related to My Services.... Read more
Affected Products : financial_services_software- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-3384
Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : commerce_balanced_payments- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-1676
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual... Read more
Affected Products : financial_services_software- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-0932
Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- Published: Apr. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4917
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-4892.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 22, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8318
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML ... Read more
Affected Products : webform- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-6734
IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same we... Read more
Affected Products : websphere_extreme_scale_client- Published: Feb. 22, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2008-3097
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.... Read more
Affected Products : tinytax_taxonomy_block_module- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2014-9461
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_download action to wp-admin/admin-ajax.php.... Read more
Affected Products : cart66_lite- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8078
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject... Read more
Affected Products : print- Published: Oct. 09, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2008-5996
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a... Read more
- Published: Jan. 28, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-4608
Cross-site scripting (XSS) vulnerability in the BE User Log (beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : be_user_log- Published: Jun. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-3978
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment a... Read more
Affected Products : lightneasy- Published: Oct. 04, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2015-6494
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mango_automation- Published: Oct. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-3923
The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session in... Read more
Affected Products : ios- Published: Sep. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2018-1392
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.... Read more
Affected Products : financial_transaction_manager- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-8897
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 b... Read more
- Published: Dec. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-5497
Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_links- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025