Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-2122

    Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.... Read more

    Affected Products : brakeman
    • EPSS Score: %0.10
    • Published: Feb. 12, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-18791

    Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.... Read more

    • EPSS Score: %0.30
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2012-1500

    Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.... Read more

    Affected Products : jira greenhopper
    • EPSS Score: %0.22
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2012-1903

    XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.... Read more

    Affected Products : community
    • EPSS Score: %0.21
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-18210

    Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: th... Read more

    Affected Products : moodle
    • EPSS Score: %0.44
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-4429

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more

    • EPSS Score: %0.24
    • Published: Feb. 19, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-8824

    Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.... Read more

    Affected Products : coda-4582u_firmware coda-4582u
    • EPSS Score: %0.28
    • Published: Feb. 19, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-9339

    SOPlanning 1.45 allows XSS via the Name or Comment to status.php.... Read more

    Affected Products : soplanning
    • EPSS Score: %0.28
    • Published: Feb. 22, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-19990

    An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /monitor/s_headmodel.p... Read more

    Affected Products : visual_access_manager
    • EPSS Score: %0.24
    • Published: Feb. 26, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-19991

    An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /vam/vam_anagraphic... Read more

    Affected Products : visual_access_manager
    • EPSS Score: %0.24
    • Published: Feb. 26, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-8951

    Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.... Read more

    Affected Products : accurate_reconciliation
    • EPSS Score: %0.28
    • Published: Feb. 26, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-9459

    Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax acti... Read more

    Affected Products : modern_events_calendar_lite
    • EPSS Score: %0.18
    • Published: Feb. 28, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-19599

    Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued product.... Read more

    Affected Products : monstra monstra_cms
    • EPSS Score: %0.35
    • Published: Mar. 02, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-19658

    The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote users; however, it is a vulnerability in YXBJ, not a vulnerability in Evernote.... Read more

    Affected Products : macos yinxiang_biji
    • EPSS Score: %0.34
    • Published: Mar. 02, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4196

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more

    • EPSS Score: %0.31
    • Published: Mar. 03, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-19222

    A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page by sending a crafted Forms/wireless_autonetwork_1 POST re... Read more

    Affected Products : dsl-2680_firmware dsl-2680
    • EPSS Score: %0.51
    • Published: Mar. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-10107

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.... Read more

    Affected Products : daily_expense_tracker_system
    • EPSS Score: %0.21
    • Published: Mar. 05, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-19772

    Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.... Read more

    • EPSS Score: %0.35
    • Published: Mar. 06, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-19773

    Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.... Read more

    • EPSS Score: %0.35
    • Published: Mar. 06, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4084

    HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more

    Affected Products : connections
    • EPSS Score: %0.34
    • Published: Mar. 09, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291384 Results