Latest CVE Feed
-
5.4
MEDIUMCVE-2019-14918
XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via crafted DHCP request packets to etc_ro/web/internet/dhcpclii... Read more
- EPSS Score: %0.19
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6303
SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.... Read more
Affected Products : disclosure_management- EPSS Score: %0.31
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2646
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Command Line Interface). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows low privilege... Read more
- EPSS Score: %0.26
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2011-3595
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.... Read more
Affected Products : joomla\!- EPSS Score: %0.03
- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.08
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-2249
Zimbra Collaboration before 8.6.0 patch5 has XSS.... Read more
Affected Products : zimbra_collaboration_server- EPSS Score: %0.70
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17651
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS)... Read more
Affected Products : fortisiem- EPSS Score: %0.20
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-5776
Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.... Read more
Affected Products : dokeos- EPSS Score: %0.19
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-0161
Havalite CMS 1.1.7 has a stored XSS vulnerability... Read more
Affected Products : havalite- EPSS Score: %0.30
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8498
XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privi... Read more
Affected Products : gistpress- EPSS Score: %0.47
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4451
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru... Read more
Affected Products : security_identity_manager- EPSS Score: %0.24
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-15253
A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interfa... Read more
- EPSS Score: %0.16
- Published: Feb. 05, 2020
- Modified: Jul. 23, 2025
-
5.4
MEDIUM- EPSS Score: %0.18
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-3636
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag... Read more
Affected Products : projectpier- EPSS Score: %0.24
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.26
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8812
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.... Read more
Affected Products : bludit- EPSS Score: %0.26
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-2207
Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) ctrl, (2) t90001_0_theform_selection, (3) _scroll, (4) tableName, (... Read more
Affected Products : resource_management_system- EPSS Score: %0.15
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-1353
Orange HRM 2.7.1 allows XSS via the vacancy name.... Read more
Affected Products : orangehrm- EPSS Score: %0.18
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-6449
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.... Read more
- EPSS Score: %0.18
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2112
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.... Read more
Affected Products : git_parameter- EPSS Score: %0.12
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024