Latest CVE Feed
-
5.4
MEDIUMCVE-2014-7398
The Dil Bilgisi Kurallari (aka com.buronya.dilbilgisi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dil_bilgisi_kurallari- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7403
The NZHondas.com (aka com.tapatalk.nzhondascom) application 3.6.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : nzhondas.com- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-6878
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.... Read more
Affected Products : metinfo- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7257
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7335
A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject arbitrary web script or HTML via non-saniti... Read more
Affected Products : fortiwlc- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-7444
The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : baidu_navigation- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7465
The PC Advisor (aka com.triactivemedia.pcadvisor) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : pc_advisor- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7472
The CSApp - Colegio San Agustin (aka com.goodbarber.csapp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : csapp_-_colegio_san_agustin- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-11276
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent requ... Read more
Affected Products : application_service- Published: Aug. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7519
The Cycling Manager Game Cff (aka com.CyclingManagerGame) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
Affected Products : cycling_manager_game_cff- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-11871
The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.... Read more
Affected Products : custom_field_suite- Published: May. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-15189
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.... Read more
Affected Products : advanced_real_estate_script- Published: Aug. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-13647
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must... Read more
Affected Products : firefly_iii- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7649
The Classic Car Buyer (aka com.magazinecloner.carbuyer) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : classic_car_buyer- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-17832
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (th... Read more
Affected Products : monitoring_software- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-16628
panel/login in Kirby v2.5.12 allows XSS via a blog name.... Read more
Affected Products : kirby- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1793
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c... Read more
Affected Products : rational_quality_manager- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14272
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.... Read more
Affected Products : silverstripe- Published: Sep. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin mana... Read more
Affected Products : nagios_xi- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1507
IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : rational_doors_next_generation- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024