Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-31914

    Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.... Read more

    • EPSS Score: %0.20
    • Published: Jun. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-31301

    Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.... Read more

    Affected Products : haraj
    • EPSS Score: %0.78
    • Published: Jun. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-36608

    Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.... Read more

    Affected Products : webtareas
    • EPSS Score: %0.18
    • Published: Jun. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-53457

    A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.... Read more

    Affected Products : librenms
    • Published: Dec. 05, 2024
    • Modified: Apr. 07, 2025
  • 5.4

    MEDIUM
    CVE-2024-11321

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learning Learning Management System (LMS) allows Reflected XSS.This issue affects Learning Management System (LMS): before 06.12.2024.... Read more

    Affected Products :
    • Published: Dec. 06, 2024
    • Modified: Dec. 06, 2024
  • 5.4

    MEDIUM
    CVE-2017-20059

    A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input </title><img src=no onerror=alert(1)> leads... Read more

    Affected Products : elefant_cms
    • EPSS Score: %0.20
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-20061

    A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to... Read more

    Affected Products : elefant_cms
    • EPSS Score: %0.18
    • Published: Jun. 20, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-12253

    The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions ... Read more

    Affected Products : simple-e-commerce-shopping-cart
    • Published: Dec. 07, 2024
    • Modified: Dec. 07, 2024
  • 5.4

    MEDIUM
    CVE-2022-31302

    maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.... Read more

    Affected Products : maccms
    • EPSS Score: %0.18
    • Published: Jun. 21, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-23868

    Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.... Read more

    Affected Products : cost_of_goods_for_woocommerce
    • Published: Dec. 09, 2024
    • Modified: Dec. 09, 2024
  • 5.4

    MEDIUM
    CVE-2021-41432

    A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.... Read more

    Affected Products : flatpress
    • EPSS Score: %5.68
    • Published: Jun. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-46824

    Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.... Read more

    Affected Products : school_file_management_system
    • EPSS Score: %0.27
    • Published: Jun. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-25469

    Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2.... Read more

    Affected Products : easy_table_of_contents
    • Published: Dec. 09, 2024
    • Modified: Dec. 09, 2024
  • 5.4

    MEDIUM
    CVE-2022-33113

    Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.... Read more

    Affected Products : jfinal_cms
    • EPSS Score: %0.18
    • Published: Jun. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-25959

    Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apollo13 Framework Extensions: from n/a through 1.8.10.... Read more

    Affected Products : apollo13_framework_extensions
    • Published: Dec. 09, 2024
    • Modified: Dec. 09, 2024
  • 5.4

    MEDIUM
    CVE-2023-29433

    Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects tencentcloud-cos: from n/a through 1.0.7.... Read more

    Affected Products :
    • Published: Dec. 09, 2024
    • Modified: Dec. 09, 2024
  • 5.4

    MEDIUM
    CVE-2017-20094

    A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgradi... Read more

    Affected Products : newstatpress
    • EPSS Score: %0.20
    • Published: Jun. 24, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-49757

    Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.... Read more

    Affected Products : awesome_support
    • Published: Dec. 09, 2024
    • Modified: May. 29, 2025
  • 5.4

    MEDIUM
    CVE-2022-27238

    BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each ... Read more

    Affected Products : bigbluebutton
    • EPSS Score: %0.20
    • Published: Jun. 24, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-20544

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitat... Read more

    Affected Products : linux_kernel windows jazz_team_server
    • EPSS Score: %0.10
    • Published: Jun. 24, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 290955 Results