Latest CVE Feed
-
5.4
MEDIUM- EPSS Score: %0.18
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-3636
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag... Read more
Affected Products : projectpier- EPSS Score: %0.24
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.26
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8812
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.... Read more
Affected Products : bludit- EPSS Score: %0.26
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-2207
Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) ctrl, (2) t90001_0_theform_selection, (3) _scroll, (4) tableName, (... Read more
Affected Products : resource_management_system- EPSS Score: %0.15
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-1353
Orange HRM 2.7.1 allows XSS via the vacancy name.... Read more
Affected Products : orangehrm- EPSS Score: %0.18
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-6449
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.... Read more
- EPSS Score: %0.18
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2112
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.... Read more
Affected Products : git_parameter- EPSS Score: %0.12
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2122
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.... Read more
Affected Products : brakeman- EPSS Score: %0.10
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18791
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.... Read more
Affected Products : cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware xm1145_firmware xm3150_firmware mx71x_firmware mx81x_firmware xm51xx_firmware +150 more products- EPSS Score: %0.30
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-1500
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.... Read more
- EPSS Score: %0.22
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-1903
XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.... Read more
Affected Products : community- EPSS Score: %0.21
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18210
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: th... Read more
Affected Products : moodle- EPSS Score: %0.44
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4429
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
- EPSS Score: %0.24
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8824
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.... Read more
- EPSS Score: %0.28
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9339
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.... Read more
Affected Products : soplanning- EPSS Score: %0.28
- Published: Feb. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19990
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /monitor/s_headmodel.p... Read more
Affected Products : visual_access_manager- EPSS Score: %0.24
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19991
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /vam/vam_anagraphic... Read more
Affected Products : visual_access_manager- EPSS Score: %0.24
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8951
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.... Read more
Affected Products : accurate_reconciliation- EPSS Score: %0.28
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9459
Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax acti... Read more
Affected Products : modern_events_calendar_lite- EPSS Score: %0.18
- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024