Latest CVE Feed
-
5.4
MEDIUMCVE-2020-29315
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.... Read more
Affected Products : thinkadmin- EPSS Score: %0.20
- Published: Dec. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16958
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.... Read more
- EPSS Score: %1.75
- Published: Dec. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-29539
A Cross-Site Scripting (XSS) issue in WebUI Translation in Systran Pure Neural Server before 9.7.0 allows a threat actor to have a remote authenticated user run JavaScript from a malicious site.... Read more
Affected Products : pure_neural_server- EPSS Score: %0.15
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25955
SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.... Read more
Affected Products : student_management_system_project_in_php- EPSS Score: %0.49
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-29259
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.... Read more
Affected Products : online_examination_system- EPSS Score: %0.21
- Published: Dec. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35201
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.... Read more
Affected Products : openfire- EPSS Score: %0.18
- Published: Dec. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35202
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.... Read more
Affected Products : openfire- EPSS Score: %0.18
- Published: Dec. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19284
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS) attacks if an attacker is able to modify content of particular web pages, causing the application to behave in unexpected ways for le... Read more
Affected Products : xhq- EPSS Score: %0.34
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-16243
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.ce... Read more
Affected Products : database_performance_analyzer- EPSS Score: %3.50
- Published: Dec. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28930
A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is execute... Read more
- EPSS Score: %0.42
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25609
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.... Read more
Affected Products : micollab- EPSS Score: %0.50
- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16955
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.... Read more
Affected Products : webhelpdesk- EPSS Score: %1.93
- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16957
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.... Read more
Affected Products : webhelpdesk- EPSS Score: %2.18
- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14478
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser... Read more
Affected Products : netcrunch- EPSS Score: %0.34
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35705
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.... Read more
Affected Products : daybyday- EPSS Score: %0.21
- Published: Dec. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35707
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.... Read more
Affected Products : daybyday- EPSS Score: %0.21
- Published: Dec. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-26035
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.... Read more
Affected Products : zammad- EPSS Score: %0.34
- Published: Dec. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-29469
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will visits the website directory, the XSS triggers and attack... Read more
Affected Products : wondercms- EPSS Score: %0.31
- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5810
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.... Read more
Affected Products : umbraco_cms- EPSS Score: %3.50
- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-29231
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visit... Read more
Affected Products : user_registration_and_login_system_with_admin_panel- EPSS Score: %0.53
- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024