Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2018-1000415

    A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.jelly, RebuildAction/FileParameterValue.jelly, RebuildAction/LabelParameterVa... Read more

    Affected Products : rebuild
    • EPSS Score: %0.20
    • Published: Jan. 09, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-16164

    Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : event_calendar_wd
    • EPSS Score: %0.21
    • Published: Jan. 09, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-20703

    CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.... Read more

    Affected Products : cubecart
    • EPSS Score: %0.21
    • Published: Jan. 13, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-0018

    A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration session, possibly tricking a follow... Read more

    • EPSS Score: %0.26
    • Published: Jan. 15, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10737

    Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.... Read more

    Affected Products : serendipity
    • EPSS Score: %0.28
    • Published: Jan. 16, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-2419

    Vulnerability in the PeopleSoft Enterprise CC Common Application Objects component of Oracle PeopleSoft Products (subcomponent: Form and Approval Builder). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileg... Read more

    • EPSS Score: %0.20
    • Published: Jan. 16, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-0482

    A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The... Read more

    Affected Products : prime_infrastructure
    • EPSS Score: %0.17
    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-1202

    IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting ... Read more

    Affected Products : bigfix_compliance
    • EPSS Score: %0.09
    • Published: Feb. 05, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-20774

    Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.... Read more

    Affected Products : frog_cms
    • EPSS Score: %0.21
    • Published: Feb. 11, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-0254

    SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more

    Affected Products : disclosure_management
    • EPSS Score: %0.32
    • Published: Feb. 15, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1895

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more

    • EPSS Score: %0.16
    • Published: Feb. 15, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-8935

    Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.... Read more

    Affected Products : collabtive
    • EPSS Score: %0.21
    • Published: Feb. 19, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-20241

    The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.... Read more

    Affected Products : crucible fisheye
    • EPSS Score: %0.23
    • Published: Feb. 20, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-16193

    Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web script or HTML via unspecified vect... Read more

    • EPSS Score: %0.29
    • Published: Jan. 09, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1912

    IBM DOORS Next Generation (DNG/RRC) 6.0.2 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials dis... Read more

    Affected Products : rational_doors_next_generation
    • EPSS Score: %0.17
    • Published: Mar. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-17425

    WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.... Read more

    Affected Products : wuzhi_cms wuzhicms
    • EPSS Score: %0.21
    • Published: Mar. 07, 2019
    • Modified: May. 05, 2025
  • 5.4

    MEDIUM
    CVE-2019-0269

    SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more

    • EPSS Score: %0.28
    • Published: Mar. 12, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1829

    IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more

    • EPSS Score: %0.23
    • Published: Mar. 14, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1910

    IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more

    • EPSS Score: %0.25
    • Published: Mar. 14, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1916

    IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially... Read more

    • EPSS Score: %0.23
    • Published: Mar. 14, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 291551 Results