Latest CVE Feed
-
5.4
MEDIUMCVE-2018-1871
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.16
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20370
SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.... Read more
Affected Products : netchat- EPSS Score: %0.21
- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1951
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- EPSS Score: %0.23
- Published: Jan. 04, 2019
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2019-0244
SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
- EPSS Score: %0.32
- Published: Jan. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-16164
Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : event_calendar_wd- EPSS Score: %0.21
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20703
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.... Read more
Affected Products : cubecart- EPSS Score: %0.21
- Published: Jan. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0018
A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration session, possibly tricking a follow... Read more
- EPSS Score: %0.26
- Published: Jan. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10737
Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.... Read more
Affected Products : serendipity- EPSS Score: %0.28
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-2419
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects component of Oracle PeopleSoft Products (subcomponent: Form and Approval Builder). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileg... Read more
- EPSS Score: %0.20
- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1202
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting ... Read more
Affected Products : bigfix_compliance- EPSS Score: %0.09
- Published: Feb. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20774
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.... Read more
Affected Products : frog_cms- EPSS Score: %0.21
- Published: Feb. 11, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0254
SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : disclosure_management- EPSS Score: %0.32
- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1895
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more
- EPSS Score: %0.16
- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8935
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.... Read more
Affected Products : collabtive- EPSS Score: %0.21
- Published: Feb. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17425
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.... Read more
- EPSS Score: %0.21
- Published: Mar. 07, 2019
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2019-0269
SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform businessobjects_business_intelligence- EPSS Score: %0.28
- Published: Mar. 12, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1910
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.25
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1916
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially... Read more
- EPSS Score: %0.23
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1761
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_team_concert- EPSS Score: %0.23
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20736
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.... Read more
Affected Products : api_manager- EPSS Score: %0.32
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024