Latest CVE Feed
-
5.4
MEDIUMCVE-2018-20636
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.... Read more
Affected Products : _auditor_website_project- EPSS Score: %0.21
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1763
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : rational_quality_manager- EPSS Score: %0.23
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20640
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field.... Read more
Affected Products : entrepreneur_job_portal_script- EPSS Score: %0.21
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20736
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.... Read more
Affected Products : api_manager- EPSS Score: %0.32
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20737
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.... Read more
- EPSS Score: %0.32
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1982
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_team_concert- EPSS Score: %0.23
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1983
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
- EPSS Score: %0.23
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7223
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CV... Read more
Affected Products : invoiceplane- EPSS Score: %0.28
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10106
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.25
- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10107
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.25
- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-3847
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added ... Read more
Affected Products : moodle- EPSS Score: %1.13
- Published: Mar. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17989
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser... Read more
- EPSS Score: %0.20
- Published: Apr. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1913
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
- EPSS Score: %0.23
- Published: Apr. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1943
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTT... Read more
Affected Products : cloud_private- EPSS Score: %0.13
- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10634
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.... Read more
- EPSS Score: %0.16
- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4148
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.16
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4238
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more
- EPSS Score: %0.17
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4029
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.23
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4033
IBM Content Navigator 2.0.3 and 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more
Affected Products : content_navigator- EPSS Score: %0.16
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4076
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.16
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024