Latest CVE Feed
-
5.4
MEDIUMCVE-2018-1911
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
Affected Products : rational_doors_next_generation- Published: Mar. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-15279
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/P... Read more
Affected Products : umbraco_cms- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUM- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1568
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering... Read more
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20875
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1678
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : rational_doors_next_generation- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16801
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.... Read more
Affected Products : octopus_deploy- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-25039
A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/RgUrlBlock.asp. The manipulation of the argument BasicParentalNewKeyword with the input ><script>alert... Read more
- Published: Jun. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-3716
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.... Read more
Affected Products : simplehttpserver- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18408
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18473
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-8178
Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability. A remote attacker could exploit this vulnerability to send email that storing malicious code to a smartphone an... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-5213
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8024
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script ... Read more
- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8326
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Open Source Customi... Read more
Affected Products : web_customizations- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-9183
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.... Read more
Affected Products : js_jobs- Published: Apr. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5553
Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL.... Read more
Affected Products : b2evolution- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5832
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.... Read more
Affected Products : revive_adserver- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-7340
The Old Bike Mart (aka com.magazinecloner.oldbike) application @7F08017E for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : old_bike_mart- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7352
The India's Anthem (aka appinventor.ai_opalfoxy83.India_Anthem) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : india\'s_anthem- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025