Latest CVE Feed
-
5.4
MEDIUMCVE-2020-17449
PHP-Fusion 9.03 allows XSS via the error_log file.... Read more
Affected Products : php-fusion- EPSS Score: %0.21
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-57329
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.... Read more
Affected Products : hortusfox- Published: Jan. 23, 2025
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2025-50817
A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2020-17372
SugarCRM before 10.1.0 (Q3 2020) allows XSS.... Read more
Affected Products : sugarcrm- EPSS Score: %0.49
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-25011
NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.... Read more
Affected Products : netbox- EPSS Score: %0.39
- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-7110
A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educar_escola_lst.php of the component School Module. The manipulation of the argument Escola leads to cross s... Read more
Affected Products : i-educar- Published: Jul. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-52386
CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-36406
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue.... Read more
Affected Products : suitecrm- Published: Jun. 10, 2024
- Modified: Aug. 12, 2025
-
5.4
MEDIUMCVE-2024-52364
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr... Read more
Affected Products : cloud_pak_for_business_automation- Published: Feb. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-41391
Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-8501
A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The manipulation of the argument content leads to cross site scripting... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-8510
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of the file ieducar/intranet/educar_matricula_lst.php. The manipulation of the argument ref_cod_aluno leads to cross site scripting. It i... Read more
Affected Products : i-educar- Published: Aug. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-29239
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read d... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-29235
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database c... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-29231
Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2025-7205
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. T... Read more
Affected Products : givewp- Published: Jul. 31, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-7818
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /category.php of the component HTTP POST Request Handler. The manipulation of ... Read more
Affected Products : apartment_visitors_management_system- Published: Jul. 19, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-49343
IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more
Affected Products : informix_dynamic_server- Published: Jul. 28, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-53519
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, p... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-41442
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's brows... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Cross-Site Scripting