Latest CVE Feed
-
5.4
MEDIUMCVE-2023-25833
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change ... Read more
Affected Products : portal_for_arcgis- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-15936
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.... Read more
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16230
In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit.... Read more
Affected Products : typecho- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-0490
The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : f\(x\)_toc- Published: May. 15, 2023
- Modified: Jan. 14, 2025
-
5.4
MEDIUMCVE-2017-14752
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profil... Read more
Affected Products : mahara- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1147
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
Affected Products : openpages_grc_platform- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1552
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, inclu... Read more
Affected Products : infosphere_biginsights- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-2768
A vulnerability was found in Sucms 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin_ads.php?action=add. The manipulation of the argument intro leads to cross site scripting. The attack may be la... Read more
Affected Products : sucms- Published: May. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30124
LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : lavalite- Published: May. 18, 2023
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2017-12294
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters... Read more
Affected Products : webex_meetings_server- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-2735
The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products : groundhogg- Published: May. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1554
IBM Infosphere BigInsights 4.2.0 and 4.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click act... Read more
Affected Products : infosphere_biginsights- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-27925
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : vk_blocks- Published: May. 23, 2023
- Modified: Jan. 17, 2025
-
5.4
MEDIUMCVE-2023-1209
Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.... Read more
Affected Products : servicenow- Published: May. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33789
A stored cross-site scripting (XSS) vulnerability in the Create Contact Groups (/tenancy/contact-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33790
A stored cross-site scripting (XSS) vulnerability in the Create Locations (/dcim/locations/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33791
A stored cross-site scripting (XSS) vulnerability in the Create Provider Accounts (/circuits/provider-accounts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33794
A stored cross-site scripting (XSS) vulnerability in the Create Tenants (/tenancy/tenants/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-16567
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users ... Read more
Affected Products : media_server- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-2945
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.... Read more
Affected Products : openemr- Published: May. 27, 2023
- Modified: Nov. 21, 2024