Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2024-7657

    A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site ... Read more

    Affected Products : gila_cms
    • Published: Aug. 12, 2024
    • Modified: Aug. 15, 2024
  • 5.4

    MEDIUM
    CVE-2025-32999

    Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this v... Read more

    Affected Products : a-blog_cms
    • Published: May. 19, 2025
    • Modified: May. 19, 2025
  • 5.4

    MEDIUM
    CVE-2025-48246

    Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Events Calendar: from n/a through 6.11.2.1.... Read more

    Affected Products :
    • Published: May. 19, 2025
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2025-26920

    Missing Authorization vulnerability in PressMaximum Customify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through 0.4.8.... Read more

    Affected Products :
    • Published: May. 19, 2025
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2025-45754

    A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.... Read more

    Affected Products : seeddms
    • Published: May. 21, 2025
    • Modified: Jun. 25, 2025
  • 5.4

    MEDIUM
    CVE-2025-47583

    Unauthenticated Cross Site Request Forgery (CSRF) in Salon booking system <= 10.16 versions.... Read more

    Affected Products : salon_booking_system
    • Published: May. 19, 2025
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2024-51108

    Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a craf... Read more

    Affected Products : medical_card_generation_system
    • Published: May. 23, 2025
    • Modified: May. 29, 2025
  • 5.4

    MEDIUM
    CVE-2022-35194

    TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.... Read more

    Affected Products : testlink
    • EPSS Score: %0.12
    • Published: Sep. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2025-5127

    A vulnerability, which was classified as problematic, has been found in FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. The manipulation of the argument cmd leads to cross site scripting. The attack may be initiat... Read more

    Affected Products : flir_ax8_firmware flir_ax8
    • Published: May. 24, 2025
    • Modified: Jun. 16, 2025
  • 5.4

    MEDIUM
    CVE-2022-37251

    Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.... Read more

    Affected Products : craft_cms
    • EPSS Score: %0.16
    • Published: Sep. 16, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-38550

    A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more

    Affected Products : jeesns
    • EPSS Score: %0.10
    • Published: Sep. 19, 2022
    • Modified: May. 27, 2025
  • 5.4

    MEDIUM
    CVE-2022-3005

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.... Read more

    • EPSS Score: %0.11
    • Published: Sep. 20, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-37339

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress.... Read more

    Affected Products : meet_my_team
    • EPSS Score: %0.08
    • Published: Sep. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-37328

    Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.... Read more

    Affected Products : timeline_awesome
    • EPSS Score: %0.06
    • Published: Sep. 23, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2025-29632

    Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components... Read more

    Affected Products : free5gc
    • Published: May. 29, 2025
    • Modified: Jun. 25, 2025
  • 5.4

    MEDIUM
    CVE-2025-48488

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripting (X... Read more

    Affected Products : freescout
    • Published: May. 30, 2025
    • Modified: Jun. 04, 2025
  • 5.4

    MEDIUM
    CVE-2025-48875

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed... Read more

    Affected Products : freescout
    • Published: May. 30, 2025
    • Modified: Jun. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-37028

    ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScript payload that will be executed when another user uses the application.... Read more

    Affected Products : isams
    • EPSS Score: %0.12
    • Published: Sep. 27, 2022
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2021-41434

    A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.... Read more

    • EPSS Score: %0.14
    • Published: Sep. 28, 2022
    • Modified: May. 20, 2025
  • 5.4

    MEDIUM
    CVE-2022-3326

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.... Read more

    Affected Products : rdiffweb
    • EPSS Score: %0.16
    • Published: Sep. 29, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 290943 Results