Latest CVE Feed
-
5.4
MEDIUMCVE-2016-1207
Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject... Read more
Affected Products : wn-g300r3_firmware wn-g300r2_firmware wn-g300r_firmware wn-g300r2 wn-g300r3 wn-g300r- EPSS Score: %0.22
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-2776
A vulnerability classified as problematic has been found in SourceCodester Gym Management System. Affected is an unknown function of the file delete_user.php. The manipulation of the argument delete_user leads to denial of service. It is possible to launc... Read more
- EPSS Score: %0.27
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39035
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin... Read more
- EPSS Score: %0.12
- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24911
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The mini... Read more
Affected Products : transposh_wordpress_translation- EPSS Score: %0.21
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2312
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to... Read more
Affected Products : student_result_or_employee_database- EPSS Score: %0.12
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.... Read more
Affected Products : kirby- EPSS Score: %0.10
- Published: Aug. 24, 2022
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2022-37245
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.... Read more
Affected Products : security_gateway_for_email_servers- EPSS Score: %0.60
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35714
IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
- EPSS Score: %0.17
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-7775
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.... Read more
Affected Products : garoon- EPSS Score: %0.22
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-31677
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what pr... Read more
Affected Products : pinniped- EPSS Score: %0.16
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36355
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <= 3.1 at WordPress.... Read more
Affected Products : easy_org_chart- EPSS Score: %0.15
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0399
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : maximo_asset_management- EPSS Score: %0.17
- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0221
Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arb... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.24
- Published: Jul. 03, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-2597
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary sav... Read more
Affected Products : visual_portfolio\,_photo_gallery_\&_post_grid- EPSS Score: %0.11
- Published: Sep. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0313
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script o... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.17
- Published: Jul. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2888
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script o... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.21
- Published: Jul. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-37253
Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter... Read more
Affected Products : crime_reporting_system- EPSS Score: %0.07
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-38639
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.... Read more
Affected Products : markdown_nice- EPSS Score: %0.11
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25295
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but ... Read more
Affected Products : gophish- EPSS Score: %0.11
- Published: Sep. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36568
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored... Read more
- EPSS Score: %0.16
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024