Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-7035

    A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\standard\templates\post.php of the component Setting Handler. The manipulation of the argument siten... Read more

    Affected Products : automad
    • EPSS Score: %0.19
    • Published: Dec. 21, 2023
    • Modified: Jun. 15, 2025
  • 5.4

    MEDIUM
    CVE-2023-7050

    A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file user/profile.php. The manipulation of the argument name/email leads to cross... Read more

    Affected Products : online_notes_sharing_system
    • EPSS Score: %0.19
    • Published: Dec. 21, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-27150

    openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.... Read more

    Affected Products : opencrx
    • EPSS Score: %0.08
    • Published: Dec. 26, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-49779

    Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.... Read more

    Affected Products : growi
    • EPSS Score: %1.29
    • Published: Dec. 26, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-50550

    layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter.... Read more

    Affected Products : layui
    • EPSS Score: %0.42
    • Published: Dec. 30, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-0189

    A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument C... Read more

    • EPSS Score: %0.07
    • Published: Jan. 02, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-0201

    The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated at... Read more

    Affected Products : product_expiry_for_woocommerce
    • EPSS Score: %0.04
    • Published: Jan. 03, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-0266

    A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the component User Registration. The manipulation of the argument First Name leads to cross site scripting. ... Read more

    • EPSS Score: %0.10
    • Published: Jan. 07, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-51252

    PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.... Read more

    Affected Products : publiccms
    • EPSS Score: %0.16
    • Published: Jan. 10, 2024
    • Modified: Jun. 20, 2025
  • 5.4

    MEDIUM
    CVE-2023-48783

    An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-... Read more

    Affected Products : fortiportal
    • EPSS Score: %0.26
    • Published: Jan. 10, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-5118

    The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author and text are not adequately sanitized and validated. Th... Read more

    Affected Products : kofax_capture
    • EPSS Score: %0.20
    • Published: Jan. 11, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-23174

    An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.44
    • Published: Jan. 12, 2024
    • Modified: Jun. 20, 2025
  • 5.4

    MEDIUM
    CVE-2023-50072

    A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a docum... Read more

    Affected Products : openkm
    • EPSS Score: %4.11
    • Published: Jan. 13, 2024
    • Modified: Jun. 03, 2025
  • 5.4

    MEDIUM
    CVE-2021-24433

    The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-s... Read more

    Affected Products : simple_sort\&search
    • EPSS Score: %0.27
    • Published: Jan. 16, 2024
    • Modified: Jun. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-2413

    The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even ... Read more

    Affected Products : slide_anything
    • EPSS Score: %0.10
    • Published: Jan. 16, 2024
    • Modified: May. 22, 2025
  • 5.4

    MEDIUM
    CVE-2023-4757

    The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory ... Read more

    • EPSS Score: %0.24
    • Published: Jan. 16, 2024
    • Modified: Jun. 20, 2025
  • 5.4

    MEDIUM
    CVE-2024-0599

    A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java of the component Document Management Page.... Read more

    Affected Products : jspxcms
    • EPSS Score: %0.18
    • Published: Jan. 16, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-20270

    A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack agai... Read more

    • EPSS Score: %0.07
    • Published: Jan. 17, 2024
    • Modified: Jun. 02, 2025
  • 5.4

    MEDIUM
    CVE-2023-38624

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ... Read more

    Affected Products : apex_central
    • EPSS Score: %0.15
    • Published: Jan. 23, 2024
    • Modified: Jun. 20, 2025
  • 5.4

    MEDIUM
    CVE-2023-38625

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ... Read more

    Affected Products : apex_central
    • EPSS Score: %0.15
    • Published: Jan. 23, 2024
    • Modified: Jun. 20, 2025
Showing 20 of 291295 Results