Latest CVE Feed
-
5.4
MEDIUMCVE-2020-14787
Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows low privileged attac... Read more
Affected Products : communications_diameter_signaling_router- EPSS Score: %0.18
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-27533
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.... Read more
Affected Products : dedecms- EPSS Score: %0.47
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-27666
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.... Read more
Affected Products : strapi- EPSS Score: %0.28
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8062
A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service.... Read more
- EPSS Score: %0.18
- Published: Oct. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6876
A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module, a remote attacker could trigger an XSS attack when the... Read more
Affected Products : evdc- EPSS Score: %0.19
- Published: Oct. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.21
- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7356
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.... Read more
Affected Products : subrion- EPSS Score: %0.25
- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9299
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.... Read more
Affected Products : dispatch- EPSS Score: %0.44
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4760
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
Affected Products : content_navigator- EPSS Score: %0.16
- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5662
Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.... Read more
Affected Products : xoonips- EPSS Score: %0.21
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5663
Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.... Read more
Affected Products : xoonips- EPSS Score: %0.20
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-13773
Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx... Read more
Affected Products : endpoint_manager- EPSS Score: %0.14
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-27988
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).... Read more
Affected Products : nagios_xi- EPSS Score: %56.62
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4672
IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : business_automation_workflow- EPSS Score: %0.24
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25834
Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).... Read more
Affected Products : arcsight_logger- EPSS Score: %0.29
- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25832
Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability could be exploited to perform Reflected XSS attack.... Read more
Affected Products : filr- EPSS Score: %0.21
- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25454
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.... Read more
- EPSS Score: %0.18
- Published: Nov. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14208
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.... Read more
Affected Products : suitecrm- EPSS Score: %0.15
- Published: Nov. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7570
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary w... Read more
Affected Products : webreports- EPSS Score: %0.19
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7571
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script ... Read more
Affected Products : webreports- EPSS Score: %0.19
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024