Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-20990

    A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.... Read more

    Affected Products : domainmod
    • EPSS Score: %0.28
    • Published: Aug. 12, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-2195

    Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.... Read more

    Affected Products : compact_columns
    • EPSS Score: %0.12
    • Published: Jun. 03, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-7485

    Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web scr... Read more

    • EPSS Score: %0.13
    • Published: Jan. 16, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-2227

    Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.... Read more

    Affected Products : deployer_framework
    • EPSS Score: %0.12
    • Published: Jul. 15, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-7474

    Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to injec... Read more

    • EPSS Score: %0.15
    • Published: Jan. 16, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-2292

    Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Release permission.... Read more

    Affected Products : release
    • EPSS Score: %0.23
    • Published: Oct. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-15317

    The give plugin before 2.4.7 for WordPress has XSS via a donor name.... Read more

    Affected Products : givewp give
    • EPSS Score: %0.33
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-15869

    The JobCareer theme before 2.5.1 for WordPress has stored XSS.... Read more

    Affected Products : jobcareer
    • EPSS Score: %0.16
    • Published: Sep. 03, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16417

    HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.... Read more

    Affected Products : hrworks
    • EPSS Score: %0.21
    • Published: Oct. 08, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-16688

    Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)... Read more

    Affected Products : dolibarr_erp\/crm
    • EPSS Score: %0.17
    • Published: Sep. 27, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-26801

    A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers to obtain other users' information via a crafted POST r... Read more

    • EPSS Score: %0.22
    • Published: Jun. 25, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-2114

    Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : office
    • EPSS Score: %0.18
    • Published: Apr. 28, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-2148

    Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : wn-ac1167gr_firmware wn-ac1167gr
    • EPSS Score: %0.24
    • Published: Apr. 28, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2013-4275

    Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "administer themes" permission to in... Read more

    Affected Products : zen
    • EPSS Score: %0.41
    • Published: Nov. 13, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2017-2256

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".... Read more

    Affected Products : garoon
    • EPSS Score: %0.25
    • Published: Aug. 29, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2019-8129

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting an embedded expression into a translation.... Read more

    Affected Products : magento
    • EPSS Score: %0.18
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-8132

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" ... Read more

    Affected Products : magento
    • EPSS Score: %0.18
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-29233

    WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and at... Read more

    Affected Products : wondercms
    • EPSS Score: %0.14
    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-28938

    OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.... Read more

    Affected Products : openclinic
    • EPSS Score: %0.21
    • Published: Dec. 03, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-35721

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are n... Read more

    • EPSS Score: %0.15
    • Published: Jan. 11, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 292387 Results