Latest CVE Feed
-
5.4
MEDIUMCVE-2013-2767
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restric... Read more
- EPSS Score: %0.52
- Published: Apr. 25, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2023-34835
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.... Read more
Affected Products : escan_management_console- EPSS Score: %1.36
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19290
A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment section.... Read more
Affected Products : jeesns- EPSS Score: %0.19
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19293
A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.... Read more
Affected Products : jeesns- EPSS Score: %0.19
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-17449
PHP-Fusion 9.03 allows XSS via the error_log file.... Read more
Affected Products : php-fusion- EPSS Score: %0.21
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-57329
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.... Read more
Affected Products : hortusfox- Published: Jan. 23, 2025
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2025-50817
A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2020-17372
SugarCRM before 10.1.0 (Q3 2020) allows XSS.... Read more
Affected Products : sugarcrm- EPSS Score: %0.49
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-25011
NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.... Read more
Affected Products : netbox- EPSS Score: %0.39
- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-7110
A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educar_escola_lst.php of the component School Module. The manipulation of the argument Escola leads to cross s... Read more
Affected Products : i-educar- Published: Jul. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-52386
CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-36406
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue.... Read more
Affected Products : suitecrm- Published: Jun. 10, 2024
- Modified: Aug. 12, 2025
-
5.4
MEDIUMCVE-2024-52364
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr... Read more
Affected Products : cloud_pak_for_business_automation- Published: Feb. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-41391
Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-8501
A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The manipulation of the argument content leads to cross site scripting... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-8510
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of the file ieducar/intranet/educar_matricula_lst.php. The manipulation of the argument ref_cod_aluno leads to cross site scripting. It i... Read more
Affected Products : i-educar- Published: Aug. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-29239
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read d... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-29235
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database c... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-29231
Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2025-7205
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. T... Read more
Affected Products : givewp- Published: Jul. 31, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting