Latest CVE Feed
-
5.4
MEDIUMCVE-2017-9555
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : photo_station- EPSS Score: %0.23
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-0408
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based manage... Read more
Affected Products : sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware sf300-24mp_firmware +46 more products- EPSS Score: %0.17
- Published: Aug. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8024
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script ... Read more
- EPSS Score: %40.68
- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8326
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Open Source Customi... Read more
Affected Products : web_customizations- EPSS Score: %0.43
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-4930
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user bein... Read more
Affected Products : airwatch- EPSS Score: %0.19
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-55093
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.... Read more
Affected Products : phpipam- Published: Mar. 31, 2025
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2018-10314
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scrip... Read more
Affected Products : open-audit- EPSS Score: %0.19
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-9183
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.... Read more
Affected Products : js_jobs- EPSS Score: %0.27
- Published: Apr. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5553
Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL.... Read more
Affected Products : b2evolution- EPSS Score: %0.22
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-7314
The Intelligent SME (aka com.magzter.intelligentsme) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : intelligent_sme- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-5832
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.... Read more
Affected Products : revive_adserver- EPSS Score: %0.23
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-7325
The Business Intelligence (aka com.magzter.businessintelligence) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : business_intelligence- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7340
The Old Bike Mart (aka com.magazinecloner.oldbike) application @7F08017E for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : old_bike_mart- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7352
The India's Anthem (aka appinventor.ai_opalfoxy83.India_Anthem) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : india\'s_anthem- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7398
The Dil Bilgisi Kurallari (aka com.buronya.dilbilgisi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dil_bilgisi_kurallari- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7403
The NZHondas.com (aka com.tapatalk.nzhondascom) application 3.6.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : nzhondas.com- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7406
The Deakin University (aka com.desire2learn.campuslife.deakin.edu.au.directory) application 1.1.729.1694 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inform... Read more
Affected Products : deakin_university- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-6878
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.... Read more
Affected Products : metinfo- EPSS Score: %0.29
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-7424
The Quran Abu Bakr AshShatiri Free (aka com.wQuranAbuBakrFREE) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : quran_abu_bakr_ashshatiri_free- EPSS Score: %0.04
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-7257
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.21
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025