Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-4218

    The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to de... Read more

    Affected Products : chained_quiz
    • Published: Dec. 02, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-45916

    ILIAS before 7.16 allows XSS.... Read more

    Affected Products : ilias
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-44731

    A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035), SIMATIC WinCC OA V3.17 (All versions < V3.17 P024), SIMATIC WinCC OA V3.18 (All versions < V3.18 P014). The affe... Read more

    Affected Products : simatic_wincc simatic_wincc_oa
    • Published: Dec. 13, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43996

    The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently... Read more

    Affected Products : csaf_provider
    • Published: Dec. 13, 2022
    • Modified: Apr. 22, 2025
  • 5.4

    MEDIUM
    CVE-2022-40373

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.... Read more

    Affected Products : feehicms
    • Published: Dec. 15, 2022
    • Modified: Apr. 21, 2025
  • 5.4

    MEDIUM
    CVE-2022-4587

    A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipulation of the arg... Read more

    Affected Products : oc-server3
    • Published: Dec. 17, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4596

    A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads t... Read more

    Affected Products : lifestyle
    • Published: Dec. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4597

    A vulnerability, which was classified as problematic, was found in Shoplazza LifeStyle 1.1. Affected is an unknown function of the file /admin/api/admin/v2_products of the component Create Product Handler. The manipulation leads to cross site scripting. I... Read more

    Affected Products : lifestyle
    • Published: Dec. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4599

    A vulnerability was found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/api/theme-edit/ of the component Product Handler. The manipulation of the argument Subheading/Headi... Read more

    Affected Products : lifestyle
    • Published: Dec. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4614

    Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11.... Read more

    Affected Products : znote
    • Published: Dec. 19, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-44380

    Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.... Read more

    Affected Products : snipe-it
    • Published: Dec. 25, 2022
    • Modified: Apr. 15, 2025
  • 5.4

    MEDIUM
    CVE-2022-29853

    OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.... Read more

    Affected Products : open-xchange_appsuite
    • Published: Dec. 26, 2022
    • Modified: Apr. 14, 2025
  • 5.4

    MEDIUM
    CVE-2019-25086

    A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cr... Read more

    Affected Products : open_media_player
    • Published: Dec. 27, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4362

    The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : popup_maker
    • Published: Jan. 02, 2023
    • Modified: Apr. 10, 2025
  • 5.4

    MEDIUM
    CVE-2022-4881

    A vulnerability was found in CapsAdmin PAC3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lua/pac3/core/shared/http.lua. The manipulation of the argument url leads to cross site scripting. The attack m... Read more

    Affected Products : pac3
    • Published: Jan. 08, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-46769

    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in ... Read more

    Affected Products : sling_cms
    • Published: Jan. 09, 2023
    • Modified: Apr. 09, 2025
  • 5.4

    MEDIUM
    CVE-2022-4497

    The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks whi... Read more

    Affected Products : jetpack_crm
    • Published: Jan. 09, 2023
    • Modified: Apr. 09, 2025
  • 5.4

    MEDIUM
    CVE-2023-0246

    A vulnerability, which was classified as problematic, was found in earclink ESPCMS P8.21120101. Affected is an unknown function of the component Content Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.... Read more

    Affected Products : espcms espcms-p8
    • Published: Jan. 12, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-46438

    A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter.... Read more

    Affected Products : douphp
    • Published: Jan. 13, 2023
    • Modified: Apr. 08, 2025
  • 5.4

    MEDIUM
    CVE-2023-0300

    Cross-site Scripting (XSS) - Reflected in GitHub repository alfio-event/alf.io prior to 2.0-M4-2301.... Read more

    Affected Products : alf.io alf
    • Published: Jan. 14, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 293508 Results