Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2014-7398

    The Dil Bilgisi Kurallari (aka com.buronya.dilbilgisi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : dil_bilgisi_kurallari
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7403

    The NZHondas.com (aka com.tapatalk.nzhondascom) application 3.6.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : nzhondas.com
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2017-6878

    Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.... Read more

    Affected Products : metinfo
    • Published: Mar. 27, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-7257

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.... Read more

    Affected Products : cms_made_simple
    • Published: Mar. 24, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-7335

    A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject arbitrary web script or HTML via non-saniti... Read more

    Affected Products : fortiwlc
    • Published: Oct. 26, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2014-7444

    The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : baidu_navigation
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7465

    The PC Advisor (aka com.triactivemedia.pcadvisor) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : pc_advisor
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7472

    The CSApp - Colegio San Agustin (aka com.goodbarber.csapp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more

    Affected Products : csapp_-_colegio_san_agustin
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2019-11276

    Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent requ... Read more

    Affected Products : application_service
    • Published: Aug. 19, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-7519

    The Cycling Manager Game Cff (aka com.CyclingManagerGame) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more

    Affected Products : cycling_manager_game_cff
    • Published: Oct. 20, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2019-11871

    The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.... Read more

    Affected Products : custom_field_suite
    • Published: May. 10, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-15189

    PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.... Read more

    Affected Products : advanced_real_estate_script
    • Published: Aug. 10, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-13647

    Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must... Read more

    Affected Products : firefly_iii
    • Published: Jul. 18, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-7649

    The Classic Car Buyer (aka com.magazinecloner.carbuyer) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more

    Affected Products : classic_car_buyer
    • Published: Oct. 21, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2017-17832

    ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (th... Read more

    Affected Products : monitoring_software
    • Published: Dec. 27, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2018-16628

    panel/login in Kirby v2.5.12 allows XSS via a blog name.... Read more

    Affected Products : kirby
    • Published: Dec. 04, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-1793

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c... Read more

    Affected Products : rational_quality_manager
    • Published: Jul. 10, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-14272

    In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.... Read more

    Affected Products : silverstripe
    • Published: Sep. 26, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-17146

    A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin mana... Read more

    Affected Products : nagios_xi
    • Published: Jun. 19, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1507

    IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more

    Affected Products : rational_doors_next_generation
    • Published: Jun. 27, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293186 Results