Latest CVE Feed
-
5.4
MEDIUMCVE-2018-19750
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.... Read more
Affected Products : domainmod- EPSS Score: %0.19
- Published: Nov. 29, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-16633
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.... Read more
Affected Products : pluck- EPSS Score: %0.21
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11348
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's session.... Read more
Affected Products : yunohost- EPSS Score: %0.20
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-12310
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.... Read more
- EPSS Score: %0.21
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1728
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- EPSS Score: %0.16
- Published: Dec. 05, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-16635
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.... Read more
Affected Products : blackcat_cms- EPSS Score: %0.21
- Published: Dec. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1900
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading ... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.23
- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8652
A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1.... Read more
Affected Products : windows_azure_pack_rollup- EPSS Score: %0.43
- Published: Dec. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1667
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript ... Read more
Affected Products : datapower_gateway- EPSS Score: %0.11
- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20306
A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted website and steal sensitive data and cr... Read more
Affected Products : virtual_traffic_manager- EPSS Score: %0.18
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000847
FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code in victim's session. This attack appear to be exploitable via The attacker st... Read more
Affected Products : freshdns- EPSS Score: %0.32
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000870
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(V... Read more
Affected Products : phpipam- EPSS Score: %0.34
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1871
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.16
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20328
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to t... Read more
Affected Products : chamilo_lms- EPSS Score: %0.25
- Published: Dec. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20370
SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.... Read more
Affected Products : netchat- EPSS Score: %0.21
- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-19992
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.15
- Published: Jan. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1951
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- EPSS Score: %0.23
- Published: Jan. 04, 2019
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2018-1918
IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.23
- Published: Jan. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0244
SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
- EPSS Score: %0.32
- Published: Jan. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000413
A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jen... Read more
Affected Products : config_file_provider- EPSS Score: %0.11
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024