Latest CVE Feed
-
5.4
MEDIUMCVE-2022-32988
Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc) in every ".asp" page containing a list of stored strings. The following asp files are affected: (1) cgi-... Read more
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32065
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.... Read more
Affected Products : ruoyi- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32318
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.... Read more
Affected Products : fast_food_ordering_system- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35261
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jul. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36552
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jul. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-31201
SoftGuard Web (SGW) before 5.1.5 allows HTML injection.... Read more
Affected Products : softguard_web- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-4256
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The ex... Read more
Affected Products : seacms- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-4326
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add Fragment Page. The manipulation leads to cross site scripting. The attack may be initiat... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-34853
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.... Read more
Affected Products : team- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-3766
The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers,... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2022-2579
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument userName with the input lala<img src="... Read more
Affected Products : garage_management_system- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2684
A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /manage-apartment.php. The manipulation of the argument Apartment Number with the i... Read more
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-9030
A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the argument notes leads to cross site scripting. The attack can be initiated r... Read more
Affected Products : crmgo_saas- Published: Sep. 20, 2024
- Modified: Sep. 25, 2024
-
5.4
MEDIUMCVE-2022-37063
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interfac... Read more
- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-9089
A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file update_loan_record.php. The manipulation of the argument amount leads to cross site scripti... Read more
Affected Products : modern_loan_management_system- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
5.4
MEDIUMCVE-2022-37243
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.... Read more
Affected Products : security_gateway_for_email_servers- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-7086
The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.... Read more
Affected Products : svg_uploads_support- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10818
The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perf... Read more
Affected Products : jsfiddle_shortcode- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-11502
The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a... Read more
Affected Products : planning_center_online_giving- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-48027
The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication