Latest CVE Feed
-
5.4
MEDIUMCVE-2020-14728
Vulnerability in the SuiteCommerce Advanced (SCA) component of Oracle NetSuite service. Supported versions that are affected are Montblanc, Vinson, Elbrus, Kilimanjaro, Aconcagua, 2018.2, 2019.1, 2019.2. Easily exploitable vulnerability allows low privile... Read more
Affected Products : suitecommerce_advanced- EPSS Score: %0.18
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14729
Vulnerability in SuiteCommerce Advanced (SCA) Sites component of Oracle NetSuite service. Supported versions that are affected are prior to 2020.1.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to comprom... Read more
Affected Products : suitecommerce_advanced- EPSS Score: %0.25
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23983
Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.... Read more
Affected Products : ichat- EPSS Score: %0.18
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23984
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.... Read more
Affected Products : online_hotel_booking_system_pro- EPSS Score: %0.18
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-12646
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.... Read more
Affected Products : open-xchange_appsuite- EPSS Score: %0.34
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-20626
lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.... Read more
Affected Products : lara\'s_google_analytics- EPSS Score: %0.47
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2238
Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.... Read more
Affected Products : git_parameter- EPSS Score: %0.23
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2244
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test b... Read more
Affected Products : build_failure_analyzer- EPSS Score: %0.17
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23450
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.... Read more
Affected Products : spiceworks- EPSS Score: %0.43
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4445
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager rational_rhapsody_design_manager rational_team_concert doors_next engineering_test_management engineering_workflow_management engineering_requirements_management_doors_next +1 more products- EPSS Score: %0.24
- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25104
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.... Read more
Affected Products : eramba- EPSS Score: %0.34
- Published: Sep. 03, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-24963
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.... Read more
Affected Products : best_support_system- EPSS Score: %0.41
- Published: Sep. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4516
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali... Read more
- EPSS Score: %0.06
- Published: Sep. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6312
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular p... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.34
- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25375
Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VA... Read more
Affected Products : wp_smart_crm_\&_invoices- EPSS Score: %0.18
- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25380
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that will be stored and executed.... Read more
Affected Products : recall-products- EPSS Score: %0.16
- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25071
Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit. Note: It has been argued that this is not reproducible. "The original issue was that the task would be created and an alert would be ... Read more
Affected Products : nifty- EPSS Score: %0.16
- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2256
Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permissi... Read more
Affected Products : pipeline_maven_integration- EPSS Score: %0.23
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2269
Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views.... Read more
Affected Products : chosen-views-tabbar- EPSS Score: %0.23
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-20406
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.... Read more
Affected Products : elementor_page_builder- EPSS Score: %0.25
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024