Latest CVE Feed
-
5.4
MEDIUMCVE-2023-6067
The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
- Published: Apr. 15, 2024
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2024-32449
Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a through 3.1.2. ... Read more
Affected Products : restropress- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32092
Cross-Site Request Forgery (CSRF) vulnerability in Michael Bester Kimili Flash Embed.This issue affects Kimili Flash Embed: from n/a through 2.5.3. ... Read more
Affected Products : kimili_flash_embed- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32096
Cross-Site Request Forgery (CSRF) vulnerability in DAEV.Tech WP Migration Plugin DB & Files – WP Synchro.This issue affects WP Migration Plugin DB & Files – WP Synchro: from n/a through 1.11.2. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32103
Cross-Site Request Forgery (CSRF) vulnerability in Siteimprove.This issue affects Siteimprove: from n/a through 2.0.6. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31373
Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf.This issue affects e2pdf: from n/a through 1.20.27. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-45808
iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for exam... Read more
Affected Products : itop- Published: Apr. 15, 2024
- Modified: Feb. 06, 2025
-
5.4
MEDIUMCVE-2021-31327
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.... Read more
Affected Products : remote_clinic- EPSS Score: %0.37
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-21070
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Search Framework). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with networ... Read more
- Published: Apr. 16, 2024
- Modified: Dec. 06, 2024
-
5.4
MEDIUMCVE-2024-32515
Missing Authorization vulnerability in Qamar Sheeraz, Nasir Ahmad Mega Addons For Elementor.This issue affects Mega Addons For Elementor: from n/a through 1.8. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31712
react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.... Read more
Affected Products : react_draft_wysiwyg- EPSS Score: %0.26
- Published: Apr. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35542
Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack.... Read more
Affected Products : data_exchange_management_studio- EPSS Score: %0.27
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20448
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
- EPSS Score: %0.14
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21365
Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability. Users of the extension, who have ove... Read more
Affected Products : typo3- EPSS Score: %0.34
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31778
The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user account.... Read more
Affected Products : media2click- EPSS Score: %0.21
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31389
Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-22790
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.... Read more
Affected Products : fme_server- EPSS Score: %0.38
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29146
A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.... Read more
- EPSS Score: %0.30
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-47731
IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th... Read more
- Published: Apr. 23, 2024
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2024-4072
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting... Read more
Affected Products : online_furniture_shopping_ecommerce_website- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024