Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0071
The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored... Read more
Affected Products : wp_tabs- EPSS Score: %0.14
- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2023-33843
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
Affected Products : infosphere_information_server- Published: Feb. 21, 2024
- Modified: Dec. 10, 2024
-
5.4
MEDIUMCVE-2022-22502
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
- EPSS Score: %0.22
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-11127
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.... Read more
- EPSS Score: %0.21
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-24840
Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11. ... Read more
Affected Products : element_pack- Published: Mar. 23, 2024
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2016-4877
Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.24
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-43742
CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.... Read more
Affected Products : cmsimple- EPSS Score: %0.20
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6817
The Cove (aka org.covechurch.app) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : cove- EPSS Score: %0.04
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-47117
IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea... Read more
Affected Products : carbon_charts- Published: Dec. 10, 2024
- Modified: Aug. 15, 2025
-
5.4
MEDIUMCVE-2025-55203
Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerability exists in the description_html field of Plane. This flaw allows an attacker to inject malicious JavaScript code that is stored and... Read more
Affected Products : plane- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-25041
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Ass... Read more
Affected Products : cognos_analytics- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-53631
flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post... Read more
Affected Products : flaskblog- Published: Aug. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2014-6767
The Juggle! FREE (aka com.jakyl.juggleforfree) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : juggle\!_free- EPSS Score: %0.04
- Published: Sep. 28, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2004-2527
The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Win... Read more
- EPSS Score: %1.00
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2005-3899
The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory duri... Read more
Affected Products : talk- EPSS Score: %1.15
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2005-3887
Gadu-Gadu 7.20 does not properly handle MS-DOS device names in filenames, which allows remote attackers to (1) cause a denial of service (hang) via an image filename of AUX: sent twice (hang), or (2) write to the LPT1 port via a filename of "LPT1:".... Read more
Affected Products : gadu-gadu_instant_messenger- EPSS Score: %1.41
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-3351
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL a... Read more
- EPSS Score: %25.50
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-4139
Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via unspecified vectors related to ifconfig and either netstat or SNMP queries.... Read more
Affected Products : solaris- EPSS Score: %0.76
- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-5179
Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra ti... Read more
- EPSS Score: %0.33
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2006-6896
The Bluetooth stack in the Plantronic Headset does not properly implement Non-pairable mode, which allows remote attackers to conduct unauthorized pair-up operations.... Read more
Affected Products : headset- EPSS Score: %0.31
- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025