Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2016-10853

    cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.26
    • Published: Aug. 01, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-1010124

    WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administr... Read more

    Affected Products : woocommerce_product_feed
    • EPSS Score: %0.32
    • Published: Jul. 23, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-20915

    cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 01, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10827

    cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.26
    • Published: Aug. 01, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-18402

    cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 02, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-18417

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 02, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-18419

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 02, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-18420

    cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 02, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-7921

    A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the product catalog ... Read more

    Affected Products : magento
    • EPSS Score: %0.10
    • Published: Aug. 02, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10774

    cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.30
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-14669

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.... Read more

    Affected Products : firefly_iii
    • EPSS Score: %0.21
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10778

    cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10782

    cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).... Read more

    Affected Products : cpanel
    • EPSS Score: %0.34
    • Published: Aug. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-12950

    An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.... Read more

    Affected Products : teampass
    • EPSS Score: %0.21
    • Published: Aug. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-14731

    An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.... Read more

    Affected Products : zentao
    • EPSS Score: %0.19
    • Published: Aug. 07, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-10373

    A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.... Read more

    Affected Products : build_pipeline
    • EPSS Score: %0.12
    • Published: Aug. 07, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-14748

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file conten... Read more

    Affected Products : osticket
    • EPSS Score: %0.52
    • Published: Aug. 07, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-14792

    The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.... Read more

    Affected Products : wp_go_maps
    • EPSS Score: %0.21
    • Published: Aug. 09, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-0334

    When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hij... Read more

    • EPSS Score: %0.26
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-17790

    Prospecta Master Data Online (MDO) 2.0 has Stored XSS.... Read more

    Affected Products : master_data_online
    • EPSS Score: %0.21
    • Published: Aug. 15, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292425 Results