Latest CVE Feed
-
5.4
MEDIUMCVE-2021-27658
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.... Read more
Affected Products : exacqvision_enterprise_manager- EPSS Score: %0.22
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-16727
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.... Read more
Affected Products : razorcms- EPSS Score: %0.19
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33966
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.... Read more
Affected Products : spotweb- EPSS Score: %0.31
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-28380
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.... Read more
Affected Products : aimeos- EPSS Score: %0.27
- Published: Mar. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-22109
In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim’s browser when ... Read more
- EPSS Score: %0.21
- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29387
Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parame... Read more
Affected Products : equipment_inventory_system- EPSS Score: %0.13
- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30039
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.... Read more
Affected Products : remote_clinic- EPSS Score: %0.15
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2008-4295
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by ... Read more
- EPSS Score: %40.75
- Published: Sep. 27, 2008
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2022-23051
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.... Read more
Affected Products : petereport- EPSS Score: %0.17
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30637
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.... Read more
Affected Products : htmly- EPSS Score: %0.15
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31274
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.... Read more
Affected Products : librenms- EPSS Score: %0.01
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31329
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php... Read more
Affected Products : remote_clinic- EPSS Score: %0.37
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37465
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).... Read more
Affected Products : quorum- EPSS Score: %0.21
- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31583
Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being... Read more
Affected Products : next_generation_communication_platform- EPSS Score: %0.30
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24588
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.... Read more
Affected Products : flatpress- EPSS Score: %0.21
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5247
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can populate this field with a filename that contains standard HTML scripting tags. The resulting scri... Read more
Affected Products : secure_file_transfer- EPSS Score: %0.22
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-3224
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.... Read more
Affected Products : csz_cms- EPSS Score: %0.17
- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-5280
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.... Read more
- EPSS Score: %0.30
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38713
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.... Read more
Affected Products : imgurl- EPSS Score: %0.17
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38822
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.... Read more
Affected Products : icehrm- EPSS Score: %0.34
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024