Latest CVE Feed
-
5.4
MEDIUMCVE-2018-16628
panel/login in Kirby v2.5.12 allows XSS via a blog name.... Read more
Affected Products : kirby- EPSS Score: %0.21
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10059
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.... Read more
Affected Products : cacti- EPSS Score: %0.29
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1793
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c... Read more
Affected Products : rational_quality_manager- EPSS Score: %0.18
- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14272
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.... Read more
Affected Products : silverstripe- EPSS Score: %0.41
- Published: Sep. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17138
The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field.... Read more
Affected Products : jibu_pro- EPSS Score: %0.15
- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin mana... Read more
Affected Products : nagios_xi- EPSS Score: %6.36
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more
Affected Products : hrsale- EPSS Score: %0.19
- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10326
PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to prin... Read more
Affected Products : printeron- EPSS Score: %0.31
- Published: May. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1507
IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : rational_doors_next_generation- EPSS Score: %0.23
- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17574
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.... Read more
Affected Products : yapi- EPSS Score: %0.21
- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14787
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.... Read more
Affected Products : newsletters- EPSS Score: %0.28
- Published: Aug. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10937
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.... Read more
Affected Products : openshift_container_platform- EPSS Score: %0.42
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-17994
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.... Read more
Affected Products : biometric_shift_employee_management_system- EPSS Score: %0.21
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-11343
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.... Read more
Affected Products : soundsgood- EPSS Score: %0.34
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11471
Cockpit 0.5.5 has XSS via a collection, form, or region.... Read more
Affected Products : cockpit- EPSS Score: %0.21
- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7739
The Anahi A Adopter FR (aka com.wAnahiAAdopterFR) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : anahi_a_adopter_fr- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7744
The Musulmanin.com (aka com.wSalyafiyailimurdjiya) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : musulmanin.com- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1891
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : security_guardium- EPSS Score: %0.23
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18082
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.... Read more
Affected Products : bamboo- EPSS Score: %0.18
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7753
The Circa News (aka cir.ca) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : circa_news- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025