Latest CVE Feed
-
5.4
MEDIUMCVE-2022-2213
A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_admin_details.php?id=admin. The manipulation of the argument... Read more
Affected Products : library_management_system- EPSS Score: %0.20
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32318
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.... Read more
Affected Products : fast_food_ordering_system- EPSS Score: %0.17
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35261
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.... Read more
Affected Products : multi_restaurant_table_reservation_system- EPSS Score: %0.34
- Published: Jul. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36552
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.... Read more
Affected Products : multi_restaurant_table_reservation_system- EPSS Score: %0.34
- Published: Jul. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-31201
SoftGuard Web (SGW) before 5.1.5 allows HTML injection.... Read more
Affected Products : softguard_web- EPSS Score: %0.26
- Published: Jul. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29788
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading ... Read more
Affected Products : engineering_requirements_quality_assistant_on-premises- EPSS Score: %0.24
- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-4256
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The ex... Read more
Affected Products : seacms- Published: May. 05, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-21572
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low ... Read more
Affected Products : communications_billing_and_revenue_management- EPSS Score: %0.20
- Published: Jul. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-4326
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add Fragment Page. The manipulation leads to cross site scripting. The attack may be initiat... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-34853
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.... Read more
Affected Products : team- EPSS Score: %0.18
- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-3766
The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers,... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2020-36290
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScr... Read more
- EPSS Score: %0.46
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2579
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument userName with the input lala<img src="... Read more
Affected Products : garage_management_system- EPSS Score: %0.21
- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26308
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.... Read more
Affected Products : pandora_fms- EPSS Score: %0.25
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-27484
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.... Read more
Affected Products : fortiadc- EPSS Score: %0.13
- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-1691
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.... Read more
Affected Products : moodle- EPSS Score: %0.51
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36861
Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews.... Read more
Affected Products : rich_review- EPSS Score: %0.10
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2684
A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /manage-apartment.php. The manipulation of the argument Apartment Number with the i... Read more
- EPSS Score: %0.20
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-9030
A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the argument notes leads to cross site scripting. The attack can be initiated r... Read more
Affected Products : crmgo_saas- Published: Sep. 20, 2024
- Modified: Sep. 25, 2024
-
5.4
MEDIUMCVE-2022-37063
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interfac... Read more
- EPSS Score: %0.49
- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024