Latest CVE Feed
-
5.4
MEDIUMCVE-2020-4557
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function... Read more
- EPSS Score: %0.24
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2201
Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation, resulting in a stored cross-site scripting vulnerability.... Read more
Affected Products : sonargraph_integration- EPSS Score: %0.09
- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2214
Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.... Read more
Affected Products : zap_pipeline- EPSS Score: %0.12
- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15514
The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.... Read more
Affected Products : jh_captcha- EPSS Score: %0.21
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15517
The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS.... Read more
- EPSS Score: %0.21
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9584
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.... Read more
Affected Products : magento- EPSS Score: %0.23
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15037
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.... Read more
Affected Products : nedi- EPSS Score: %0.21
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15028
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.... Read more
Affected Products : nedi- EPSS Score: %0.34
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15030
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.... Read more
Affected Products : nedi- EPSS Score: %0.34
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15031
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.... Read more
Affected Products : nedi- EPSS Score: %0.34
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7576
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2), Opcenter Execution Core (V8.2). An authenticated user with the ability to create containers, packages or register defects cou... Read more
Affected Products : opcenter_execution_core- EPSS Score: %0.47
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4091
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "... Read more
Affected Products : marketing_campaign- EPSS Score: %0.34
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15885
A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.... Read more
- EPSS Score: %0.27
- Published: Jul. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4317
IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web... Read more
- EPSS Score: %0.18
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).... Read more
- EPSS Score: %0.31
- Published: Jul. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19453
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wow... Read more
Affected Products : streaming_engine- EPSS Score: %0.44
- Published: Aug. 03, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4396
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
- EPSS Score: %0.18
- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4525
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
- EPSS Score: %0.24
- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15597
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.... Read more
Affected Products : soplanning- EPSS Score: %0.21
- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-16266
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of a... Read more
Affected Products : mantisbt- EPSS Score: %0.27
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024