Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2019-18223

    ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role Add form, (4) name or number field in the Edit Group for... Read more

    Affected Products : call_recording
    • EPSS Score: %0.57
    • Published: Apr. 27, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-10093

    A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.... Read more

    • EPSS Score: %0.35
    • Published: Apr. 28, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-10944

    HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.... Read more

    Affected Products : nomad
    • EPSS Score: %0.28
    • Published: Apr. 28, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-12261

    Open-AudIT 3.3.0 allows an XSS attack after login.... Read more

    Affected Products : open-audit
    • EPSS Score: %0.30
    • Published: Apr. 28, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-17557

    It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.... Read more

    Affected Products : syncope
    • EPSS Score: %1.19
    • Published: May. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-12629

    include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.... Read more

    Affected Products : osticket osticket
    • EPSS Score: %0.22
    • Published: May. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4384

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more

    • EPSS Score: %0.18
    • Published: May. 06, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5751

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.... Read more

    Affected Products : tcexam
    • EPSS Score: %0.16
    • Published: May. 07, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4195

    IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's clic... Read more

    Affected Products : api_connect
    • EPSS Score: %0.09
    • Published: May. 12, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-6256

    SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.... Read more

    Affected Products : master_data_governance
    • EPSS Score: %0.13
    • Published: May. 12, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-6257

    SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.... Read more

    • EPSS Score: %0.16
    • Published: May. 12, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13239

    The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.... Read more

    Affected Products : dolibarr_erp\/crm
    • EPSS Score: %0.23
    • Published: May. 20, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-8789

    Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.... Read more

    Affected Products : composr
    • EPSS Score: %0.20
    • Published: May. 22, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13459

    An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.... Read more

    Affected Products : image_resizer
    • EPSS Score: %0.21
    • Published: May. 25, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13644

    An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inje... Read more

    Affected Products : accordion
    • EPSS Score: %0.25
    • Published: May. 28, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4023

    The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.... Read more

    Affected Products : crucible fisheye
    • EPSS Score: %0.37
    • Published: Jun. 01, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13864

    The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.... Read more

    Affected Products : elementor_page_builder
    • EPSS Score: %0.13
    • Published: Jun. 05, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13865

    The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attri... Read more

    Affected Products : elementor_page_builder
    • EPSS Score: %0.13
    • Published: Jun. 05, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13890

    The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.... Read more

    Affected Products : neon
    • EPSS Score: %0.21
    • Published: Jun. 06, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13911

    Your Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation.... Read more

    Affected Products : your_online_shop
    • EPSS Score: %0.42
    • Published: Jun. 09, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291401 Results