Latest CVE Feed
-
5.4
MEDIUMCVE-2023-32536
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- EPSS Score: %0.38
- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-32537
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- EPSS Score: %0.38
- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-32604
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- EPSS Score: %0.38
- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26274
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
- EPSS Score: %0.14
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-34837
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.... Read more
Affected Products : escan_management_console- EPSS Score: %1.58
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3331
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N... Read more
- EPSS Score: %0.11
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-51330
PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.... Read more
Affected Products : cinema_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-51337
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.... Read more
Affected Products : event_ticketing_system- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-32607
Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : pleasanter- EPSS Score: %0.30
- Published: Jun. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-1577
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /prostatus.php. The manipulation of the argument message leads to cross site scri... Read more
- Published: Feb. 23, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2020-22152
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.... Read more
Affected Products : fuel_cms- EPSS Score: %0.43
- Published: Jul. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-36223
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.... Read more
Affected Products : bbs-go- EPSS Score: %0.20
- Published: Jul. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30322
Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to execute arbitrary code.... Read more
Affected Products : chatengine- EPSS Score: %0.12
- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37122
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.... Read more
Affected Products : bagecms- EPSS Score: %0.08
- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37133
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : eyoucms- EPSS Score: %0.08
- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3538
A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The att... Read more
Affected Products : photo_gallery_php- EPSS Score: %0.06
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-29998
A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.... Read more
Affected Products : g3w-suite- EPSS Score: %0.07
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-2964
The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.... Read more
Affected Products : simple_iframe- EPSS Score: %0.16
- Published: Jul. 10, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-37658
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS... Read more
Affected Products : fast-poster- EPSS Score: %0.08
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.48
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024