Latest CVE Feed
-
5.4
MEDIUMCVE-2020-14444
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.... Read more
- EPSS Score: %0.22
- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14445
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.... Read more
- EPSS Score: %0.22
- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4281
IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred... Read more
- EPSS Score: %0.18
- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-11070
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.... Read more
Affected Products : mattermost_server- EPSS Score: %0.34
- Published: Jun. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14073
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with Vie... Read more
Affected Products : prtg_network_monitor- EPSS Score: %0.84
- Published: Jun. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14006
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.... Read more
- EPSS Score: %1.06
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-13248
BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx.... Read more
Affected Products : boolebox- EPSS Score: %0.34
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4223
IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
- EPSS Score: %0.18
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4557
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function... Read more
- EPSS Score: %0.24
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15514
The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.... Read more
Affected Products : jh_captcha- EPSS Score: %0.21
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15517
The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS.... Read more
- EPSS Score: %0.21
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9584
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.... Read more
Affected Products : magento- EPSS Score: %0.23
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15028
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.... Read more
Affected Products : nedi- EPSS Score: %0.34
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15031
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.... Read more
Affected Products : nedi- EPSS Score: %0.34
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7576
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2), Opcenter Execution Core (V8.2). An authenticated user with the ability to create containers, packages or register defects cou... Read more
Affected Products : opcenter_execution_core- EPSS Score: %0.47
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15885
A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.... Read more
- EPSS Score: %0.27
- Published: Jul. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).... Read more
- EPSS Score: %0.31
- Published: Jul. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4396
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
- EPSS Score: %0.18
- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4525
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
- EPSS Score: %0.24
- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5620
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.... Read more
Affected Products : exment- EPSS Score: %0.20
- Published: Aug. 25, 2020
- Modified: Nov. 21, 2024