Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2024-37671

    Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter.... Read more

    Affected Products : docubase
    • Published: Jun. 21, 2024
    • Modified: Mar. 14, 2025
  • 5.4

    MEDIUM
    CVE-2024-37672

    Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.... Read more

    Affected Products : docubase
    • Published: Jun. 21, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-37673

    Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.... Read more

    Affected Products : docubase
    • Published: Jun. 21, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-28831

    Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.... Read more

    Affected Products : checkmk checkmk
    • Published: Jun. 25, 2024
    • Modified: Dec. 04, 2024
  • 5.4

    MEDIUM
    CVE-2021-36788

    The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.... Read more

    Affected Products : yoast_seo
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-36819

    MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is display... Read more

    Affected Products : map-os
    • Published: Jun. 25, 2024
    • Modified: Jul. 03, 2025
  • 5.4

    MEDIUM
    CVE-2024-6367

    A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp of the component POST Request Handler. T... Read more

    • Published: Jun. 27, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-37741

    OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.... Read more

    Affected Products : openplc_v3_firmware openplc_v3
    • Published: Jun. 28, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-23737

    Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.... Read more

    Affected Products : s-notify
    • Published: Jul. 01, 2024
    • Modified: Mar. 18, 2025
  • 5.4

    MEDIUM
    CVE-2024-39119

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.... Read more

    Affected Products : idccms idccms
    • Published: Jul. 02, 2024
    • Modified: Apr. 15, 2025
  • 5.4

    MEDIUM
    CVE-2024-39143

    A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload.... Read more

    Affected Products : residencecms
    • Published: Jul. 02, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-38344

    A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. A... Read more

    Affected Products :
    • Published: Jul. 04, 2024
    • Modified: Dec. 06, 2024
  • 5.4

    MEDIUM
    CVE-2024-29318

    Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.... Read more

    Affected Products : personal_management_system
    • Published: Jul. 05, 2024
    • Modified: Mar. 13, 2025
  • 5.4

    MEDIUM
    CVE-2024-39019

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?mudi=del... Read more

    Affected Products : idccms idccms
    • Published: Jul. 05, 2024
    • Modified: Apr. 15, 2025
  • 5.4

    MEDIUM
    CVE-2020-19704

    A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.... Read more

    Affected Products : spring-boot-admin
    • Published: Aug. 26, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-29744

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more

    • Published: Aug. 27, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-38144

    An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a form via the submission_id parameter, e.g., clients/forms/edit_submission.php?form_id=1&view_id=1&submission_id=[XSS].... Read more

    Affected Products : core
    • Published: Aug. 31, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-20347

    WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.... Read more

    Affected Products : wtcms
    • Published: Sep. 01, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-35006

    IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more

    Affected Products : cpe security_qradar_edr
    • Published: Jul. 10, 2024
    • Modified: Sep. 15, 2025
  • 5.4

    MEDIUM
    CVE-2020-19294

    A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comments section.... Read more

    Affected Products : jeesns
    • Published: Sep. 09, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 294348 Results