Latest CVE Feed
-
5.4
MEDIUMCVE-2023-49757
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
5.4
MEDIUMCVE-2022-27238
BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each ... Read more
Affected Products : bigbluebutton- EPSS Score: %0.20
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20544
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitat... Read more
- EPSS Score: %0.10
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29865
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the vi... Read more
- EPSS Score: %0.08
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38871
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- EPSS Score: %0.22
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-54217
Missing Authorization vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.1.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2020-27509
Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. Th... Read more
Affected Products : galaxkey- EPSS Score: %0.27
- Published: Jun. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-23896
Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).... Read more
Affected Products : admidio- EPSS Score: %0.20
- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20113
A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been dis... Read more
Affected Products : server- EPSS Score: %0.18
- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20117
A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be lau... Read more
Affected Products : server- EPSS Score: %0.28
- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20122
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on o... Read more
Affected Products : bitrix_site_manager- EPSS Score: %0.20
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20036
A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the component Bounce Rule. The manipulation leads to cross site scripting (Persistent). It is possible to launch... Read more
Affected Products : phplist- EPSS Score: %0.20
- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-33043
A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute arbitrary web scripts or HTML via a crafted excel file.... Read more
Affected Products : urtracker- EPSS Score: %0.20
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-11971
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argum... Read more
Affected Products : jpress- Published: Nov. 28, 2024
- Modified: Dec. 03, 2024
-
5.4
MEDIUMCVE-2022-32988
Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc) in every ".asp" page containing a list of stored strings. The following asp files are affected: (1) cgi-... Read more
- EPSS Score: %0.19
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-3650
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.... Read more
Affected Products : jboss_aerogear- EPSS Score: %0.16
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-3172
EidoGo is susceptible to Cross-Site Scripting (XSS) attacks via maliciously crafted SGF input.... Read more
Affected Products : eidogo- EPSS Score: %0.18
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32065
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.... Read more
Affected Products : ruoyi- EPSS Score: %0.42
- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2396
A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>ale... Read more
Affected Products : simple_e-learning_system- EPSS Score: %0.21
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2213
A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_admin_details.php?id=admin. The manipulation of the argument... Read more
Affected Products : library_management_system- EPSS Score: %0.20
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024