Latest CVE Feed
-
5.4
MEDIUMCVE-2020-20990
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.... Read more
Affected Products : domainmod- EPSS Score: %0.28
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2195
Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.... Read more
Affected Products : compact_columns- EPSS Score: %0.12
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-7485
Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web scr... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.13
- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2227
Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.... Read more
Affected Products : deployer_framework- EPSS Score: %0.12
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-7474
Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to injec... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.15
- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2292
Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Release permission.... Read more
Affected Products : release- EPSS Score: %0.23
- Published: Oct. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-15317
The give plugin before 2.4.7 for WordPress has XSS via a donor name.... Read more
- EPSS Score: %0.33
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-15869
The JobCareer theme before 2.5.1 for WordPress has stored XSS.... Read more
Affected Products : jobcareer- EPSS Score: %0.16
- Published: Sep. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16417
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.... Read more
Affected Products : hrworks- EPSS Score: %0.21
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16688
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.17
- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-26801
A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers to obtain other users' information via a crafted POST r... Read more
- EPSS Score: %0.22
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-2114
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : office- EPSS Score: %0.18
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2148
Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.24
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2013-4275
Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "administer themes" permission to in... Read more
Affected Products : zen- EPSS Score: %0.41
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-2256
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".... Read more
Affected Products : garoon- EPSS Score: %0.25
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2019-8129
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting an embedded expression into a translation.... Read more
Affected Products : magento- EPSS Score: %0.18
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8132
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" ... Read more
Affected Products : magento- EPSS Score: %0.18
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-29233
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and at... Read more
Affected Products : wondercms- EPSS Score: %0.14
- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28938
OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.... Read more
Affected Products : openclinic- EPSS Score: %0.21
- Published: Dec. 03, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35721
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are n... Read more
Affected Products : policy_authority_for_unified_communications- EPSS Score: %0.15
- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024