Latest CVE Feed
-
3.5
LOWCVE-2014-0178
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potenti... Read more
Affected Products : samba- Published: May. 28, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8378
Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the "administer content types" or "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related t... Read more
Affected Products : tablefield- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-30261
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) ... Read more
- Published: Apr. 04, 2024
- Modified: Dec. 18, 2024
-
3.5
LOWCVE-2014-8376
Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows remote authenticated users with the "Administer contexts" Context UI module permission to inject arbitrary web scri... Read more
Affected Products : site_banner- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8349
Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the _20_body parameter in the comment field in an uploaded file.... Read more
Affected Products : liferay_portal- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6148
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sen... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5273
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/s... Read more
Affected Products : phpmyadmin- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-38870
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.... Read more
Affected Products :- Published: Jul. 17, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-5274
Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.... Read more
- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3096
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : curam_social_program_management- Published: Jan. 10, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3034
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to inject arbitrar... Read more
Affected Products : emptoris_contract_management- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7217
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ENUM value that is improperly ha... Read more
Affected Products : phpmyadmin- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-0875
Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that r... Read more
- Published: Jul. 07, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6592
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via vectors related to SAML, a different vulnerability than CVE-2015-0389.... Read more
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8302
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via vectors related to dashboard.... Read more
Affected Products : splunk- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5174
The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : netweaver_business_warehouse- Published: Jul. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7811
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API.... Read more
- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5313
Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8326
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table ... Read more
- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6121
Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote auth... Read more
- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025