Latest CVE Feed
-
5.4
MEDIUMCVE-2024-48708
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.... Read more
Affected Products : collabtive- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
5.4
MEDIUMCVE-2021-24950
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and... Read more
Affected Products : insight_core- EPSS Score: %0.14
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-20269
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. T... Read more
- Published: Oct. 23, 2024
- Modified: Oct. 31, 2024
-
5.4
MEDIUMCVE-2024-20300
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. T... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2021-39055
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- EPSS Score: %0.22
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-20364
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected de... Read more
- Published: Oct. 23, 2024
- Modified: Oct. 31, 2024
-
5.4
MEDIUMCVE-2024-20403
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. T... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 26, 2024
-
5.4
MEDIUMCVE-2024-46994
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes this issue.... Read more
Affected Products : basercms- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
5.4
MEDIUMCVE-2022-0704
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.... Read more
Affected Products : pimcore- EPSS Score: %0.03
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-10348
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the component Manage Tenant Details. The manipulation of the ar... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.4
MEDIUMCVE-2024-9630
The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.5.4. This makes it possible for unauthenticated attackers to view the messages t... Read more
- Published: Oct. 25, 2024
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2022-0475
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19... Read more
Affected Products : otrs- EPSS Score: %0.52
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0423
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads i... Read more
Affected Products : 3d_flipbook- EPSS Score: %0.30
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-27090
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.... Read more
Affected Products : cscms- EPSS Score: %0.13
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26197
Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.... Read more
Affected Products : joget_dx- EPSS Score: %0.50
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0595
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- EPSS Score: %12.96
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50423
Missing Authorization vulnerability in Templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through 3.1.5.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2022-1075
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site ... Read more
Affected Products : college_website_management_system- EPSS Score: %0.18
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1087
A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profile Module. The manipulation of the field Title with script tags leads to persistent cross site scripting. The attack may be initiated re... Read more
Affected Products : htmly- EPSS Score: %0.30
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26244
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.... Read more
Affected Products : hospital\'s_patient_records_management_system- EPSS Score: %0.18
- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024