Latest CVE Feed
-
5.4
MEDIUMCVE-2020-11516
Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and th... Read more
Affected Products : contact-form-7-datepicker- EPSS Score: %0.34
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11508
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka... Read more
Affected Products : wp_lead_plus_x- EPSS Score: %0.17
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4740
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.16
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4746
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.18
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11556
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.... Read more
Affected Products : snmpc_online- EPSS Score: %0.28
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11714
eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location.... Read more
- EPSS Score: %0.30
- Published: Apr. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9460
Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.... Read more
- EPSS Score: %2.30
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6221
Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.25
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6226
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.32
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6231
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.32
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19390
The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues.... Read more
Affected Products : workspace_management- EPSS Score: %0.28
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-20693
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.... Read more
- EPSS Score: %0.06
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11823
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.31
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4749
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more
- EPSS Score: %0.16
- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11416
JetBrains Space through 2020-04-22 allows stored XSS in Chats.... Read more
Affected Products : space- EPSS Score: %0.01
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7642
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.... Read more
Affected Products : lazysizes- EPSS Score: %0.34
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18702
NETGEAR R6220 devices before 1.1.0.60 are affected by incorrect configuration of security settings.... Read more
- EPSS Score: %0.07
- Published: Apr. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-21231
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.57, D6220 before 1.0.0.40, D6400 before 1.0.0.74, D7000 before 1.0.1.60, D7800 before 1.0.1.... Read more
Affected Products : wndr4500_firmware dgn2200_firmware r7800_firmware d7000_firmware ex6200_firmware ex7000_firmware jr6150_firmware pr2000_firmware r6050_firmware r6220_firmware +106 more products- EPSS Score: %0.07
- Published: Apr. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18223
ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role Add form, (4) name or number field in the Edit Group for... Read more
Affected Products : call_recording- EPSS Score: %0.57
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-10093
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.... Read more
Affected Products : cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware xm1145_firmware xm3150_firmware mx71x_firmware mx81x_firmware xm51xx_firmware +150 more products- EPSS Score: %0.35
- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024