Latest CVE Feed
-
5.4
MEDIUMCVE-2020-35973
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.... Read more
Affected Products : zzcms- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-28382
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.... Read more
Affected Products : manageengine_key_manager_plus- Published: Jun. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-24663
Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.... Read more
Affected Products : crestbridge- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27479
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.... Read more
Affected Products : defibrillator_dashboard- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35761
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.... Read more
Affected Products : bloofoxcms- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24339
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.... Read more
Affected Products : pods- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-20391
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.... Read more
Affected Products : getsimplecms- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-18664
Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.... Read more
Affected Products : web_port- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3939
The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : ditty- Published: May. 27, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2021-35501
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.... Read more
Affected Products : pandora_fms- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37411
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more
Affected Products : aspera_faspex- Published: May. 28, 2024
- Modified: Jan. 14, 2025
-
5.4
MEDIUMCVE-2024-33807
A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 28, 2024
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2024-35548
A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentat... Read more
Affected Products :- Published: May. 28, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3269
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated a... Read more
Affected Products : download_monitor- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20477
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : planning_analytics- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35468
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : human_resource_management_system- Published: May. 30, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2020-4935
IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2470
The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : simple_ajax_chat- Published: Jun. 04, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2020-23208
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.... Read more
Affected Products : phplist- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-47513
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.... Read more
Affected Products : ari_stream_quiz- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024