Latest CVE Feed
-
2.6
LOWCVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.... Read more
Affected Products : drupal- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-5710
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.... Read more
Affected Products : wordpress- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4726
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.... Read more
Affected Products : coldfusion- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-0069
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.... Read more
- Published: Mar. 08, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3738
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content... Read more
Affected Products : mambo_site_server- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4210
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these deta... Read more
Affected Products : phpay- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4739
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php.... Read more
Affected Products : jetbox_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2025-46570
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (... Read more
Affected Products : vllm- Published: May. 29, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
2.6
LOWCVE-2007-0286
Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.... Read more
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1786
Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is n... Read more
Affected Products : document_server- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-5854
Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-0021
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of servic... Read more
Affected Products : http_server- Published: Jan. 28, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-2518
Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_cnt_plainhtml] parameter to include/inc_tmpl/content/cnt6.inc.php.... Read more
Affected Products : phpwcms- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2519
Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arbitrary local files via .. (dot dot) sequences in the spaw_root parameter. NOTE: CVE analysis suggests that this is... Read more
Affected Products : phpwcms- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4570
Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or... Read more
- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-1823
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.7 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML by modifying a document head... Read more
- Published: May. 29, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-0286
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.... Read more
Affected Products : opengoo- Published: Jan. 27, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2538
IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reload... Read more
- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2348
Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.... Read more
Affected Products : e-business_designer- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-0455
Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbitrary web script or HTML via the username parameter to comment.php.... Read more
Affected Products : glfusion- Published: Feb. 11, 2009
- Modified: Apr. 09, 2025