Latest CVE Feed
-
5.4
MEDIUMCVE-2024-12650
An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not affected other applications.... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-searc... Read more
Affected Products : koha- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38758
Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient function in the templates/ingredients/view.html, models/ingredients.py, and vi... Read more
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-2150
The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email... Read more
Affected Products : c\&cm\@il- Published: Mar. 10, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-4282
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticat... Read more
Affected Products : embedpress- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-51320
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-38687
Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaS... Read more
Affected Products : svelecte- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-39599
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.... Read more
Affected Products : csz_cms- Published: Aug. 22, 2023
- Modified: Dec. 12, 2024
-
5.4
MEDIUMCVE-2023-40876
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.... Read more
Affected Products : dedecms- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-40753
There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.... Read more
Affected Products : ticket_support_script- Published: Aug. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-2375
A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file /profile.php of the component Admin Profile Page. The manipulation of the argume... Read more
- Published: Mar. 17, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-34637
A stored cross-site scripting (XSS) vulnerability in IsarNet AG IsarFlow v5.23 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the dashboard title parameter in the IsarFlow Portal.... Read more
Affected Products : isarflow- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-36387
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections. ... Read more
Affected Products : superset- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-8400
A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed... Read more
Affected Products : chuanhuchatgpt- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-41593
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.... Read more
Affected Products : dairy_farm_shop_management_system- Published: Sep. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41160
A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers to inject arbitrary web script or HTML via the key name field while adding an authorized key.... Read more
Affected Products : usermin- Published: Sep. 14, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-5025
A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the component MARC. The manipulation leads to cross site scripting. The attack ... Read more
Affected Products : koha- Published: Sep. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-23957
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4... Read more
Affected Products : identity_portal- Published: Sep. 19, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41048
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross site scripting vulnerability for SVG images. A security ho... Read more
- Published: Sep. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43331
A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
Affected Products : small_crm- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024