Latest CVE Feed
-
2.6
LOWCVE-2006-1906
Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : phplister- EPSS Score: %6.99
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-3975
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a li... Read more
- EPSS Score: %0.36
- Published: Oct. 03, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-5256
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.... Read more
Affected Products : limesurvey- EPSS Score: %0.26
- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1878
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : topsites- EPSS Score: %0.95
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-0046
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML via the title att... Read more
Affected Products : ember.js- EPSS Score: %0.52
- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2003-1582
Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by i... Read more
Affected Products : internet_information_server- EPSS Score: %4.96
- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-2712
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : wicket- EPSS Score: %4.02
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1903
Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila allow remote attackers to inject arbitrary web script or HTML (1) via the referer parameter in sendMail, and via attributes of (2) the A element and certain other HTML elements in web ... Read more
Affected Products : manila- EPSS Score: %0.34
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-6502
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a n... Read more
Affected Products : internet_explorer- EPSS Score: %6.50
- Published: Jan. 22, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-0363
Cross-site scripting (XSS) vulnerability in Zeus Web Server before 4.3r5, when SSL is enabled for the admin server, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2002-1785.... Read more
Affected Products : zeus_web_server- EPSS Score: %0.22
- Published: Jan. 20, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain... Read more
Affected Products : datapower_gateway- EPSS Score: %0.21
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2005-1678
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick user... Read more
- EPSS Score: %4.25
- Published: May. 20, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1778
Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.41
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.... Read more
Affected Products : drupal- EPSS Score: %0.65
- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-1696
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750 and 0.760RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) skin or (2) paletteid parameter to demo.php in the Xanthia module, or (3) the serverName parameter... Read more
Affected Products : postnuke- EPSS Score: %0.30
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-1905
The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a dat... Read more
Affected Products : db2- EPSS Score: %0.50
- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-1772
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the... Read more
- EPSS Score: %59.44
- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-3622
Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.... Read more
Affected Products : mdaemon- EPSS Score: %1.05
- Published: Jul. 09, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-1536
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a ser... Read more
- EPSS Score: %52.48
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-5710
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.... Read more
Affected Products : wordpress- EPSS Score: %3.13
- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025