Latest CVE Feed
-
5.4
MEDIUMCVE-2019-4740
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.16
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4746
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.18
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11556
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.... Read more
Affected Products : snmpc_online- EPSS Score: %0.28
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9460
Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.... Read more
- EPSS Score: %2.30
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6221
Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.25
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6226
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.32
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6231
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.32
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11823
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.31
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11416
JetBrains Space through 2020-04-22 allows stored XSS in Chats.... Read more
Affected Products : space- EPSS Score: %0.01
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-10093
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.... Read more
Affected Products : cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware xm1145_firmware xm3150_firmware mx71x_firmware mx81x_firmware xm51xx_firmware +150 more products- EPSS Score: %0.35
- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17557
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.... Read more
Affected Products : syncope- EPSS Score: %1.19
- Published: May. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4384
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more
- EPSS Score: %0.18
- Published: May. 06, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5751
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.... Read more
Affected Products : tcexam- EPSS Score: %0.16
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4195
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's clic... Read more
Affected Products : api_connect- EPSS Score: %0.09
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6256
SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.... Read more
Affected Products : master_data_governance- EPSS Score: %0.13
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8789
Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.... Read more
Affected Products : composr- EPSS Score: %0.20
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4023
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.... Read more
- EPSS Score: %0.37
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-13865
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attri... Read more
Affected Products : elementor_page_builder- EPSS Score: %0.16
- Published: Jun. 05, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6266
SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.... Read more
Affected Products : fiori- EPSS Score: %0.17
- Published: Jun. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11838
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or informatio... Read more
Affected Products : arcsight_management_center- EPSS Score: %0.21
- Published: Jun. 16, 2020
- Modified: Nov. 21, 2024