Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-25270

    PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.... Read more

    Affected Products : hostel_management_system
    • EPSS Score: %0.21
    • Published: Oct. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-25271

    PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.... Read more

    • EPSS Score: %0.18
    • Published: Oct. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-2289

    Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.... Read more

    Affected Products : active_choices
    • EPSS Score: %0.20
    • Published: Oct. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-6272

    SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered... Read more

    Affected Products : commerce_cloud
    • EPSS Score: %0.16
    • Published: Oct. 15, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-6368

    SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication informatio... Read more

    • EPSS Score: %0.38
    • Published: Oct. 15, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-26672

    Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.... Read more

    Affected Products : testimonial_rotator
    • EPSS Score: %0.18
    • Published: Oct. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13893

    Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web script or HTML via multiple parameters through Unicode Transformations (Best-fit Mapping), as demonstrated by the fu... Read more

    Affected Products : easypay
    • EPSS Score: %0.39
    • Published: Oct. 18, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-14787

    Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows low privileged attac... Read more

    • EPSS Score: %0.18
    • Published: Oct. 21, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-27533

    A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.... Read more

    Affected Products : dedecms
    • EPSS Score: %0.47
    • Published: Oct. 22, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-27666

    Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.... Read more

    Affected Products : strapi
    • EPSS Score: %0.28
    • Published: Oct. 22, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-8062

    A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service.... Read more

    Affected Products : ar-5387un_firmware ar-5387un
    • EPSS Score: %0.18
    • Published: Oct. 23, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-6876

    A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module, a remote attacker could trigger an XSS attack when the... Read more

    Affected Products : evdc
    • EPSS Score: %0.19
    • Published: Oct. 26, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-23868

    NeDi 1.9C allows inc/rt-popup.php d XSS.... Read more

    Affected Products : nedi
    • EPSS Score: %0.21
    • Published: Nov. 02, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-7356

    Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.... Read more

    Affected Products : subrion
    • EPSS Score: %0.25
    • Published: Nov. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-9299

    There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.... Read more

    Affected Products : dispatch
    • EPSS Score: %0.44
    • Published: Nov. 09, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4760

    IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more

    Affected Products : content_navigator
    • EPSS Score: %0.16
    • Published: Nov. 10, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5662

    Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.... Read more

    Affected Products : xoonips
    • EPSS Score: %0.21
    • Published: Nov. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5663

    Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.... Read more

    Affected Products : xoonips
    • EPSS Score: %0.20
    • Published: Nov. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-13773

    Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx... Read more

    Affected Products : endpoint_manager
    • EPSS Score: %0.14
    • Published: Nov. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-27988

    Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).... Read more

    Affected Products : nagios_xi
    • EPSS Score: %56.62
    • Published: Nov. 16, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291368 Results