Latest CVE Feed
-
5.4
MEDIUMCVE-2024-54179
IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr... Read more
Affected Products : business_automation_workflow- Published: Mar. 03, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-51457
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the inte... Read more
- Published: Jan. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-3910
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.... Read more
- Published: Apr. 29, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-8975
A vulnerability was identified in givanz Vvveb up to 1.0.5. This affects an unknown part of the file admin/template/content/edit.tpl. The manipulation of the argument slug leads to cross site scripting. It is possible to initiate the attack remotely. The ... Read more
Affected Products : vvveb- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-45315
A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.... Read more
Affected Products : hortusfox- Published: Aug. 13, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6725
In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to be re-rendered.... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2014-6712
The Airlines International (aka org.iata.IAMagazine) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : airlines_international- Published: Sep. 25, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-28002
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by us... Read more
Affected Products : textpattern- Published: Aug. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6719
The Kayak Angler Magazine (aka air.com.yudu.ReaderAIR1360155) application 3.12.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : kayak_angler_magazine- Published: Sep. 26, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2025-7791
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site s... Read more
Affected Products : online_security_guards_hiring_system- Published: Jul. 18, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2021-28114
Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.... Read more
Affected Products : froala_editor- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42485
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions.... Read more
Affected Products : gallery_with_thumbnail_slider- Published: Mar. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6853
The Foxit MobilePDF - PDF Reader (aka com.foxit.mobile.pdf.lite) application 2.2.0.0616 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craft... Read more
- Published: Oct. 01, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-37308
The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This ... Read more
Affected Products : cooked- Published: Jun. 13, 2024
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2014-6862
The ArtAcces (aka cat.gencat.mobi.artacces) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : artacces- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-28378
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.... Read more
Affected Products : gitea- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-31698
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self... Read more
Affected Products : bludit- Published: May. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-36312
There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0.... Read more
Affected Products : callback_widget- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-31757
DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'... Read more
Affected Products : dedecms- Published: May. 19, 2023
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2023-31779
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.... Read more
Affected Products : wekan- Published: May. 22, 2023
- Modified: Jan. 28, 2025