Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-28930

    A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is execute... Read more

    • EPSS Score: %0.42
    • Published: Dec. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-25609

    The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.... Read more

    Affected Products : micollab
    • EPSS Score: %0.50
    • Published: Dec. 18, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16955

    SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.... Read more

    Affected Products : webhelpdesk
    • EPSS Score: %1.93
    • Published: Dec. 18, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16957

    SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.... Read more

    Affected Products : webhelpdesk
    • EPSS Score: %2.18
    • Published: Dec. 18, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-14478

    AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser... Read more

    Affected Products : netcrunch
    • EPSS Score: %0.34
    • Published: Dec. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-35705

    Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.... Read more

    Affected Products : daybyday
    • EPSS Score: %0.21
    • Published: Dec. 25, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-35707

    Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.... Read more

    Affected Products : daybyday
    • EPSS Score: %0.21
    • Published: Dec. 25, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-26035

    An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.... Read more

    Affected Products : zammad
    • EPSS Score: %0.34
    • Published: Dec. 28, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-29469

    WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will visits the website directory, the XSS triggers and attack... Read more

    Affected Products : wondercms
    • EPSS Score: %0.31
    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5810

    A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.... Read more

    Affected Products : umbraco_cms
    • EPSS Score: %3.50
    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-29231

    EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visit... Read more

    • EPSS Score: %0.53
    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-25797

    LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser.... Read more

    Affected Products : limesurvey
    • EPSS Score: %0.26
    • Published: Dec. 31, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16956

    SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.... Read more

    Affected Products : webhelpdesk web_help_desk
    • EPSS Score: %1.93
    • Published: Jan. 04, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16954

    SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.... Read more

    Affected Products : web_help_desk
    • EPSS Score: %1.43
    • Published: Jan. 06, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16962

    Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.... Read more

    Affected Products : manageengine_desktop_central
    • EPSS Score: %2.18
    • Published: Jan. 06, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-8280

    A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.... Read more

    Affected Products : contacts
    • EPSS Score: %0.22
    • Published: Jan. 06, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4663

    IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more

    • EPSS Score: %0.24
    • Published: Jan. 08, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-27262

    Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability exists in the affected products that allow an attacker to inject arbitrary web script or HTML via the filename parameter to multiple upda... Read more

    • EPSS Score: %0.16
    • Published: Jan. 08, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4691

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more

    • EPSS Score: %0.24
    • Published: Jan. 08, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4697

    IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more

    • EPSS Score: %0.24
    • Published: Jan. 08, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291368 Results