Latest CVE Feed
-
5.4
MEDIUMCVE-2017-1146
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
Affected Products : content_navigator- EPSS Score: %0.23
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11594
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.... Read more
Affected Products : loomio- EPSS Score: %0.23
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1208
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- EPSS Score: %0.27
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12269
A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web UI of the affected so... Read more
Affected Products : spark- EPSS Score: %0.36
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1234
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.27
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1249
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- EPSS Score: %0.20
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1338
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
- EPSS Score: %0.27
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1372
IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.20
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-13724
On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the "Basic Settings" page.... Read more
- EPSS Score: %0.21
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-9438
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.... Read more
Affected Products : display-widgets- EPSS Score: %0.23
- Published: Sep. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0303
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : tivoli_integrated_portal- EPSS Score: %0.17
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0331
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or... Read more
- EPSS Score: %0.20
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0336
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-... Read more
Affected Products : security_identity_manager- EPSS Score: %0.13
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-0346
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML vi... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.20
- Published: Jul. 03, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-14985
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.php.... Read more
Affected Products : eyesofnetwork- EPSS Score: %0.15
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1553
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : infosphere_biginsights- EPSS Score: %0.27
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1567
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
- EPSS Score: %0.32
- Published: Jan. 26, 2018
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2016-10777
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).... Read more
Affected Products : cpanel- EPSS Score: %0.32
- Published: Aug. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1629
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially ... Read more
- EPSS Score: %0.22
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10993
The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter.... Read more
Affected Products : scoreme- EPSS Score: %6.28
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024