Latest CVE Feed
-
5.4
MEDIUMCVE-2025-39552
Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.200.... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2023-47309
Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::displayAjaxSavePhoneMobile.... Read more
Affected Products : gls- Published: Nov. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48087
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.... Read more
Affected Products : xxl-job- Published: Nov. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48088
xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.... Read more
Affected Products : xxl-job- Published: Nov. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48197
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.... Read more
- Published: Nov. 15, 2023
- Modified: Jun. 11, 2025
-
5.4
MEDIUMCVE-2023-48649
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.... Read more
- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48302
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, when a user is tricked into copy pasting... Read more
- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-6442
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/ful... Read more
Affected Products : nipah_virus_testing_management_system- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-6463
A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument first_na... Read more
Affected Products : user_registration_and_login_system- Published: Dec. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-46498
Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat allows Cross Site Request Forgery. This issue affects Zalo Official Live Chat: from n/a through 1.0.0.... Read more
Affected Products :- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2023-24050
Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string when setting the Wi-Fi password in the admin panel.... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48940
A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : daicuo- Published: Dec. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46857
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with asset... Read more
Affected Products : squidex- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48828
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.... Read more
Affected Products : time_slots_booking_calendar- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41171
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).... Read more
Affected Products : ngeniusone- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41905
NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user.... Read more
Affected Products : ngeniusone- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29362
A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.... Read more
- Published: May. 25, 2022
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2006-3224
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the oper... Read more
Affected Products : safari- Published: Jun. 26, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2023-46935
eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.... Read more
Affected Products : eyoucms- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-4900
The migme (aka com.projectgoth) application 4.03.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : migme- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025