Latest CVE Feed
-
5.4
MEDIUMCVE-2023-40678
Missing Authorization vulnerability in Lasso Simple URLs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through 117.... Read more
Affected Products : simple_urls- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2023-41688
Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5.... Read more
Affected Products : bulk_noindex_\&_nofollow_toolkit- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2024-54311
Missing Authorization vulnerability in i.lychkov Mark New Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark New Posts: from n/a through 7.5.1.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2024-55992
Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through 1.4.4.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
5.4
MEDIUMCVE-2024-55998
Missing Authorization vulnerability in dusthazard Popup Surveys & Polls for WordPress (Mare.io) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through 1.36... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
5.4
MEDIUMCVE-2020-4933
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20446
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35592
Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against o... Read more
Affected Products : pi-hole- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-55056
A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.... Read more
Affected Products : online_birth_certificate_system- Published: Dec. 17, 2024
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2021-27559
The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.... Read more
Affected Products : monica- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-12121
The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
5.4
MEDIUMCVE-2024-5955
Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orc... Read more
Affected Products :- Published: Dec. 20, 2024
- Modified: Dec. 20, 2024
-
5.4
MEDIUMCVE-2024-56364
SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13.... Read more
Affected Products :- Published: Dec. 23, 2024
- Modified: Dec. 23, 2024
-
5.4
MEDIUMCVE-2024-12933
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file updateItemController.php. The manipulation of the argument p_name/p_desc leads to cross s... Read more
Affected Products : simple_admin_panel- Published: Dec. 26, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2020-4975
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi... Read more
Affected Products : rational_doors_next_generation rational_quality_manager rational_team_concert engineering_requirements_quality_assistant_on-premises doors_next engineering_lifecycle_management engineering_test_management engineering_workflow_management engineering_lifecycle_optimization global_configuration_management- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-13074
A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the a... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2024-13080
A vulnerability was found in PHPGurukul Land Record System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/aboutus.php. The manipulation of the argument Page Description leads to cross site scripting. It is poss... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2023-46616
Missing Authorization vulnerability in NSquared Draw Attention allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Draw Attention: from n/a through 2.0.15.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2021-28088
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.... Read more
Affected Products : impresscms- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-37925
Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery