Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5692
The Safeway (aka com.safeway.client.android.safeway) application 4.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : safeway- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5698
The Furdiburb (aka com.sheado.lite.pet) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : furdiburb- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5701
The Skout: Chats. Friends. Fun. (aka com.skout.android) application 4.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
Affected Products : skout\- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5716
The GUNSHIP BATTLE : Helicopter 3D (aka com.theonegames.gunshipbattle) application 1.1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craf... Read more
Affected Products : gunship_battle\- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-38267
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_... Read more
- EPSS Score: %0.18
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4235
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : tivoli_netcool\/impact- EPSS Score: %0.16
- Published: Mar. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5729
The Viddy (aka com.viddy.Viddy) application 1.3.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : viddy- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-5875
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.... Read more
Affected Products : dotcms- EPSS Score: %0.28
- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUM- EPSS Score: %0.29
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5730
The russkoe TB HD (aka com.videotelecom.russkoeHD) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : russkoe_tb_hd- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-44043
An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their ow... Read more
Affected Products : app_studio- EPSS Score: %0.44
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38708
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.... Read more
Affected Products : composr_cms- EPSS Score: %0.50
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-30596
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.... Read more
- EPSS Score: %0.92
- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38752
A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.... Read more
Affected Products : online_catering_reservation_system- EPSS Score: %0.21
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-2003
Vulnerability in the Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Dashboards). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerab... Read more
Affected Products : business_intelligence- EPSS Score: %0.18
- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5736
The Buy Coins (aka com.wBuyCoins) application 0.62.13364.24150 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : buy_coins- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5742
The Eversnap Private Photo Album (aka com.weddingsnap.android) application 1.0.23 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer... Read more
Affected Products : eversnap_private_photo_album- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-30837
Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=save_recipient, vehicle_name.... Read more
- EPSS Score: %0.20
- Published: May. 24, 2022
- Modified: Feb. 24, 2025
-
5.4
MEDIUMCVE-2019-4090
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."... Read more
Affected Products : marketing_campaign- EPSS Score: %0.34
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4098
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
Affected Products : cloud_pak_system- EPSS Score: %0.24
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024