Latest CVE Feed
-
5.4
MEDIUMCVE-2022-21481
Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Financial Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
Affected Products : peoplesoft_enterprise- EPSS Score: %0.18
- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24864
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injecte... Read more
Affected Products : origin_website- EPSS Score: %0.29
- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26673
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.... Read more
- EPSS Score: %0.21
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38903
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be execu... Read more
- EPSS Score: %0.14
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38946
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure ... Read more
- EPSS Score: %0.69
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27703
Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2022-0398
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which ... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- EPSS Score: %0.07
- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-28169
Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2024-45879
The file upload function in the "QWKalkulation" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerab... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-28450
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.... Read more
Affected Products : nopcommerce- EPSS Score: %0.15
- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1503
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> lea... Read more
Affected Products : getsimple_cms- EPSS Score: %0.18
- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50841
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and t... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2024-50837
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and username parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2024-52505
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot.... Read more
Affected Products : matrix_irc_bridge- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2021-3987
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the ... Read more
Affected Products : calibre-web- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.4
MEDIUMCVE-2024-49759
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Access" page allows authenticated users to inject arbitrary JavaScript through the "bill_name" parameter when... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-49764
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inject arbitrary JavaScript through the "hostname" paramete... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-50350
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when creating ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-50352
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-51496
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vul... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 21, 2024