Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24871
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : get_custom_field_values- EPSS Score: %0.30
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-6036
IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
- EPSS Score: %0.23
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-44317
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.... Read more
- EPSS Score: %0.21
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44263
Gurock TestRail before 7.2.4 mishandles HTML escaping.... Read more
Affected Products : testrail- EPSS Score: %0.59
- Published: Dec. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19770
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.... Read more
- EPSS Score: %0.19
- Published: Dec. 21, 2021
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2016-3015
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi... Read more
Affected Products : cognos_analytics- EPSS Score: %0.26
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-4317
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.... Read more
Affected Products : confluence- EPSS Score: %0.22
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-45673
Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P before 1.3.3.140, and RAX75 before 1.0... Read more
Affected Products : r6900p_firmware r7000_firmware r7000p_firmware r7900_firmware r8000_firmware rax200_firmware rax75_firmware rax80_firmware r7000 r7900 +6 more products- EPSS Score: %0.20
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-22293
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.31
- Published: Jan. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-8927
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.23
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9979
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.26
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8298
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.... Read more
Affected Products : canvas- EPSS Score: %0.19
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8376
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.... Read more
- EPSS Score: %0.32
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8762
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.... Read more
- EPSS Score: %0.32
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-0893
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs... Read more
Affected Products : nextcloud_server- EPSS Score: %0.22
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3032
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi... Read more
Affected Products : cognos_analytics- EPSS Score: %0.24
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6035
IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- EPSS Score: %0.26
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-0603
A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: An... Read more
Affected Products : android- EPSS Score: %0.07
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-4880
Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.24
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-4883
Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.24
- Published: May. 12, 2017
- Modified: Apr. 20, 2025