Latest CVE Feed
-
2.6
LOWCVE-2024-30252
Livemarks is a browser extension that provides RSS feed bookmark folders. Versions of Livemarks prior to 3.7 are vulnerable to cross-site request forgery. A malicious website may be able to coerce the extension to send an authenticated GET request to an a... Read more
Affected Products :- Published: Apr. 04, 2024
- Modified: Aug. 27, 2025
-
2.6
LOWCVE-2025-47794
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system m... Read more
Affected Products : notes- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
2.6
LOWCVE-2012-3368
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by ru... Read more
Affected Products : dtach- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-2262
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : singapore- Published: May. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2519
Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arbitrary local files via .. (dot dot) sequences in the spaw_root parameter. NOTE: CVE analysis suggests that this is... Read more
Affected Products : phpwcms- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2538
IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reload... Read more
- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2165
Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_i... Read more
Affected Products : avactis_shopping_cart- Published: May. 04, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-4249
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters... Read more
Affected Products : cutenews- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-4409
The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attacke... Read more
Affected Products : seil\/b1- Published: Dec. 23, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2518
Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_cnt_plainhtml] parameter to include/inc_tmpl/content/cnt6.inc.php.... Read more
Affected Products : phpwcms- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-1614
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form... Read more
Affected Products : leap- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-4652
The (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and standalone mode is disabled, allow remote attackers to cause a denial of service (application crash) by sending the MOT... Read more
- Published: Feb. 26, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-3300
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attacker... Read more
- Published: Nov. 06, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2013-4504
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.... Read more
- Published: May. 13, 2014
- Modified: Aug. 27, 2025
-
2.6
LOWCVE-2008-4164
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.... Read more
Affected Products : memht_portal- Published: Sep. 22, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2015-4744
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote attackers... Read more
Affected Products : fusion_middleware- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-4231
IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.... Read more
Affected Products : irfanview- Published: Aug. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4259
Cross-site scripting (XSS) vulnerability in index.php in Fotopholder 1.8 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this might be resultant from a directory traversal vulnerability.... Read more
Affected Products : fotopholder- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-3455
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers... Read more
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-1787
The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyE... Read more
Affected Products : openssl- Published: Mar. 19, 2015
- Modified: Apr. 12, 2025