Latest CVE Feed
-
5.4
MEDIUMCVE-2018-11343
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.... Read more
Affected Products : soundsgood- EPSS Score: %0.34
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11471
Cockpit 0.5.5 has XSS via a collection, form, or region.... Read more
Affected Products : cockpit- EPSS Score: %0.21
- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7739
The Anahi A Adopter FR (aka com.wAnahiAAdopterFR) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : anahi_a_adopter_fr- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7744
The Musulmanin.com (aka com.wSalyafiyailimurdjiya) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : musulmanin.com- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1891
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : security_guardium- EPSS Score: %0.23
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18082
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.... Read more
Affected Products : bamboo- EPSS Score: %0.18
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7753
The Circa News (aka cir.ca) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : circa_news- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-12094
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : dimofinf_cms- EPSS Score: %0.46
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7758
The AMKAMAL Science Portfolio (aka com.wAMKAMALSciencePortfolio) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : amkamal_science_portfolio- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7761
The Ink Cards (aka com.sincerely.android.ink) application 2.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ink_cards- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7763
The Listen up! mirucho (aka jp.ameba.kiiteyo.android) application 1.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : listen_up\!_mirucho- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7767
The A+ (aka cn.xrzcm) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : a\+- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-16289
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.... Read more
Affected Products : woody_ad_snippets- EPSS Score: %0.42
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-19554
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.... Read more
Affected Products : dotcms- EPSS Score: %0.16
- Published: Nov. 26, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-2883
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerabili... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.17
- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1999008
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with XSS co... Read more
Affected Products : october- EPSS Score: %0.33
- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1999021
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to t... Read more
- EPSS Score: %0.21
- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17577
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.32
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-3054
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.... Read more
Affected Products : filenet_workplace- EPSS Score: %0.17
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-20285
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php... Read more
Affected Products : zzcms- EPSS Score: %6.07
- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024