Latest CVE Feed
-
3.5
LOWCVE-2010-0606
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.... Read more
Affected Products : osticket- Published: Feb. 11, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0716
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated user... Read more
Affected Products : sharepoint_server- Published: Feb. 26, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-4547
IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended a... Read more
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2010-0801
Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory traversal sequences in the controller p... Read more
- Published: Mar. 02, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2008-4002
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-1978
Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before 5.x-1.0 rc3 module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via node titles related to unspecified product features, a different vector than CVE... Read more
- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2008-3301
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow... Read more
Affected Products : bilboblog- Published: Jul. 25, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2006-0810
Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.... Read more
Affected Products : skate_board- Published: Feb. 21, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2008-3331
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.... Read more
Affected Products : mantis- Published: Jul. 27, 2008
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2025-3635
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.... Read more
Affected Products : moodle- Published: Apr. 25, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2025-3513
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : sureforms- Published: May. 02, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-23073
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted the master branch of MediaWiki’s GlobalBlocking Ext... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2023-50458
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.... Read more
Affected Products : dradis- Published: Jul. 10, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2025-48219
O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gpp field of a Cellular-Network-Info SIP header, aka an ECI (E-UTRAN Cell Iden... Read more
Affected Products :- Published: May. 18, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2025-53862
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.... Read more
Affected Products : ansible_automation_platform- Published: Jul. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2025-22445
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
3.5
LOWCVE-2025-1525
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1523
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2013-4995
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row in... Read more
Affected Products : phpmyadmin- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4428
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to ... Read more
- Published: Oct. 27, 2013
- Modified: Apr. 11, 2025