Latest CVE Feed
-
5.4
MEDIUMCVE-2019-10107
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.25
- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-3847
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added ... Read more
Affected Products : moodle- EPSS Score: %1.13
- Published: Mar. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17989
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser... Read more
- EPSS Score: %0.20
- Published: Apr. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1913
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
- EPSS Score: %0.23
- Published: Apr. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1943
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTT... Read more
Affected Products : cloud_private- EPSS Score: %0.13
- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10634
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.... Read more
- EPSS Score: %0.16
- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4148
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.16
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4238
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more
- EPSS Score: %0.17
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4029
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.23
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4033
IBM Content Navigator 2.0.3 and 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more
Affected Products : content_navigator- EPSS Score: %0.16
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4076
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.16
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-9709
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if t... Read more
Affected Products : mahara- EPSS Score: %0.32
- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20838
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.... Read more
Affected Products : amp_for_wp- EPSS Score: %0.32
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-18872
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories U... Read more
Affected Products : calendar- EPSS Score: %0.18
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7411
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Fo... Read more
Affected Products : launcher- EPSS Score: %0.12
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-12190
XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.... Read more
Affected Products : webpanel- EPSS Score: %0.21
- Published: May. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-7827
A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session.... Read more
Affected Products : d6220_firmware d6220l_firmware d6230_firmware d6230l_firmware imes19-1i_firmware imes19-1s_firmware imes19-1p_firmware ime119-1i_firmware ime119-1s_firmware ime119-1p_firmware +108 more products- EPSS Score: %0.23
- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-13668
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).... Read more
Affected Products : open-xchange_appsuite- EPSS Score: %0.34
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-11560
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded ... Read more
Affected Products : manageengine_opmanager- EPSS Score: %1.78
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10325
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.... Read more
Affected Products : warnings_next_generation- EPSS Score: %0.07
- Published: May. 31, 2019
- Modified: Nov. 21, 2024