Latest CVE Feed
-
5.4
MEDIUMCVE-2016-7419
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.... Read more
- EPSS Score: %0.20
- Published: Sep. 17, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-41358
A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.... Read more
Affected Products : garage_management_system- EPSS Score: %0.28
- Published: Oct. 20, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2022-39350
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Due to the common practice of providing v... Read more
Affected Products : dependency-track_frontend- EPSS Score: %0.12
- Published: Oct. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37781
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.... Read more
Affected Products : employee_record_management_system- EPSS Score: %0.48
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2022-43165
A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Va... Read more
Affected Products : rukovoditel- EPSS Score: %5.36
- Published: Oct. 28, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2022-43166
A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Na... Read more
Affected Products : rukovoditel- EPSS Score: %6.37
- Published: Oct. 28, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2022-43167
A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into t... Read more
Affected Products : rukovoditel- EPSS Score: %7.09
- Published: Oct. 28, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2022-43170
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injec... Read more
Affected Products : rukovoditel- EPSS Score: %6.54
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2016-3001
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability th... Read more
Affected Products : connections- EPSS Score: %0.20
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3006
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability th... Read more
Affected Products : connections- EPSS Score: %0.20
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-39026
U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) at... Read more
Affected Products : u-office_force- EPSS Score: %0.06
- Published: Oct. 31, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3096
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators... Read more
Affected Products : wp_total_hacks- EPSS Score: %0.15
- Published: Oct. 31, 2022
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2016-3003
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability th... Read more
Affected Products : connections- EPSS Score: %0.20
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-4058
Cross-site scripting (XSS) vulnerability in Huawei Policy Center before V100R003C10SPC020 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to "special characters on pages."... Read more
- EPSS Score: %0.09
- Published: Sep. 27, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-5398
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.... Read more
Affected Products : jboss_bpm_suite- EPSS Score: %0.19
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7363
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote adminis... Read more
- EPSS Score: %0.33
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-41435
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public ... Read more
Affected Products : luci- EPSS Score: %0.10
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2022-40223
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.... Read more
Affected Products : searchwp- EPSS Score: %0.16
- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-41208
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limit... Read more
Affected Products : financial_consolidation- EPSS Score: %0.29
- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36776
IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d... Read more
- EPSS Score: %0.22
- Published: Nov. 11, 2022
- Modified: Nov. 21, 2024