Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-27509

    Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. Th... Read more

    Affected Products : galaxkey
    • EPSS Score: %0.27
    • Published: Jun. 26, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-23896

    Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).... Read more

    Affected Products : admidio
    • EPSS Score: %0.20
    • Published: Jun. 28, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-20113

    A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been dis... Read more

    Affected Products : server
    • EPSS Score: %0.18
    • Published: Jun. 29, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-20117

    A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be lau... Read more

    Affected Products : server
    • EPSS Score: %0.28
    • Published: Jun. 29, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-20122

    A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on o... Read more

    Affected Products : bitrix_site_manager
    • EPSS Score: %0.20
    • Published: Jun. 30, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-20036

    A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the component Bounce Rule. The manipulation leads to cross site scripting (Persistent). It is possible to launch... Read more

    Affected Products : phplist
    • EPSS Score: %0.20
    • Published: Jun. 10, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-33043

    A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute arbitrary web scripts or HTML via a crafted excel file.... Read more

    Affected Products : urtracker
    • EPSS Score: %0.20
    • Published: Jun. 30, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-11971

    A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argum... Read more

    Affected Products : jpress
    • Published: Nov. 28, 2024
    • Modified: Dec. 03, 2024
  • 5.4

    MEDIUM
    CVE-2022-32988

    Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc) in every ".asp" page containing a list of stored strings. The following asp files are affected: (1) cgi-... Read more

    Affected Products : dsl-n14u-b1_firmware dsl-n14u-b1
    • EPSS Score: %0.19
    • Published: Jul. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-3650

    Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.... Read more

    Affected Products : jboss_aerogear
    • EPSS Score: %0.16
    • Published: Jul. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-3172

    EidoGo is susceptible to Cross-Site Scripting (XSS) attacks via maliciously crafted SGF input.... Read more

    Affected Products : eidogo
    • EPSS Score: %0.18
    • Published: Jul. 06, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-32065

    An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.... Read more

    Affected Products : ruoyi
    • EPSS Score: %0.42
    • Published: Jul. 13, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-2396

    A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>ale... Read more

    Affected Products : simple_e-learning_system
    • EPSS Score: %0.21
    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-2213

    A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_admin_details.php?id=admin. The manipulation of the argument... Read more

    Affected Products : library_management_system
    • EPSS Score: %0.20
    • Published: Jun. 27, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-32318

    Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.... Read more

    Affected Products : fast_food_ordering_system
    • EPSS Score: %0.17
    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-35261

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.... Read more

    • EPSS Score: %0.34
    • Published: Jul. 15, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-36552

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.... Read more

    • EPSS Score: %0.34
    • Published: Jul. 15, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-31201

    SoftGuard Web (SGW) before 5.1.5 allows HTML injection.... Read more

    Affected Products : softguard_web
    • EPSS Score: %0.26
    • Published: Jul. 17, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-29788

    IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading ... Read more

    • EPSS Score: %0.24
    • Published: Jul. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2025-4256

    A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The ex... Read more

    Affected Products : seacms
    • Published: May. 05, 2025
    • Modified: Jun. 12, 2025
Showing 20 of 290954 Results