Latest CVE Feed
-
5.4
MEDIUMCVE-2020-8824
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.... Read more
- EPSS Score: %0.28
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9339
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.... Read more
Affected Products : soplanning- EPSS Score: %0.28
- Published: Feb. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19990
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /monitor/s_headmodel.p... Read more
Affected Products : visual_access_manager- EPSS Score: %0.24
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19991
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /vam/vam_anagraphic... Read more
Affected Products : visual_access_manager- EPSS Score: %0.24
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8951
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.... Read more
Affected Products : accurate_reconciliation- EPSS Score: %0.28
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9459
Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax acti... Read more
Affected Products : modern_events_calendar_lite- EPSS Score: %0.18
- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19222
A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page by sending a crafted Forms/wireless_autonetwork_1 POST re... Read more
- EPSS Score: %0.51
- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-10107
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.... Read more
Affected Products : daily_expense_tracker_system- EPSS Score: %0.21
- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19773
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.... Read more
Affected Products : cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware xm1145_firmware xm3150_firmware mx71x_firmware mx81x_firmware xm51xx_firmware +150 more products- EPSS Score: %0.35
- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4608
IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
- EPSS Score: %0.21
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.... Read more
Affected Products : piwigo- EPSS Score: %0.17
- Published: Mar. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11456
LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).... Read more
Affected Products : limesurvey- EPSS Score: %0.24
- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19095
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.... Read more
Affected Products : esoms- EPSS Score: %0.30
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2175
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by ... Read more
Affected Products : fitnesse- EPSS Score: %0.16
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11516
Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and th... Read more
Affected Products : contact-form-7-datepicker- EPSS Score: %0.34
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11508
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka... Read more
Affected Products : wp_lead_plus_x- EPSS Score: %0.17
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4740
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.16
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4746
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.18
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-11556
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.... Read more
Affected Products : snmpc_online- EPSS Score: %0.28
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9460
Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.... Read more
- EPSS Score: %2.30
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024