Latest CVE Feed
-
2.6
LOWCVE-2006-2891
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary HTML or web script via the loginmessage parameter.... Read more
Affected Products : pixelpost- EPSS Score: %0.49
- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2258
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter.... Read more
Affected Products : maxxschedule- EPSS Score: %0.62
- Published: May. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2163
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.... Read more
Affected Products : pinnacle_cart- EPSS Score: %0.51
- Published: May. 04, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-3574
Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) la... Read more
- EPSS Score: %1.48
- Published: Aug. 10, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-1521
Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.35
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5069
Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : typo3- EPSS Score: %0.54
- Published: Sep. 28, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2012-5183
The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.... Read more
Affected Products : loctouch- EPSS Score: %0.29
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-0227
Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.... Read more
- EPSS Score: %0.07
- Published: Jan. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-2219
Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.... Read more
- EPSS Score: %15.09
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-2140
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.... Read more
Affected Products : appliance_platform_agent- EPSS Score: %0.11
- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2012-6582
Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain remote attackers to inject arbitrary web script or HTML via a stopforumspam.com API response, which is logged by the... Read more
- EPSS Score: %0.52
- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2005-0329
Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.... Read more
Affected Products : zipgenius- EPSS Score: %0.85
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-2414
Unspecified vulnerability in the (1) Sun Convergence 1 and (2) Sun Java Communications Suite 7 components in Oracle Sun Products Suite 1.0 and 7.0 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : sun_products_suite- EPSS Score: %0.38
- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-1999-0031
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.... Read more
- EPSS Score: %2.94
- Published: Jul. 08, 1997
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-3562
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.... Read more
Affected Products : xerver- EPSS Score: %0.85
- Published: Oct. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2012-5349
Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.... Read more
- EPSS Score: %4.55
- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
2.6
LOW- Published: Sep. 11, 2024
- Modified: Jul. 02, 2025
-
2.6
LOWCVE-2001-1353
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.... Read more
Affected Products : ghostscript- EPSS Score: %0.07
- Published: Sep. 18, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-1515
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) article-id parameter in conjunction with a /admin/news/article/list PA... Read more
Affected Products : tomatocms- EPSS Score: %0.31
- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-5477
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.... Read more
Affected Products : drupal- EPSS Score: %0.66
- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025