Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-31506

    A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.... Read more

    Affected Products : grav
    • Published: Feb. 09, 2024
    • Modified: Jun. 16, 2025
  • 5.4

    MEDIUM
    CVE-2014-7693

    The JusApp! (aka com.tapatalk.jusappcombrforum) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : jusapp\!
    • Published: Oct. 21, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7716

    The Ultimate Christian Radios (aka com.ngg.ultimatechristianradios) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted... Read more

    Affected Products : ultimate_christian_radios
    • Published: Oct. 21, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7734

    The Reds Anytime Bail (aka com.onesolutionapps.redsanytimebailandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte... Read more

    Affected Products : reds_anytime_bail
    • Published: Oct. 21, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2022-4649

    The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : wp_extended_search
    • Published: Jan. 30, 2023
    • Modified: Mar. 28, 2025
  • 5.4

    MEDIUM
    CVE-2014-7796

    The House365 Radio (aka com.nobexinc.wls_27853803.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : house365_radio
    • Published: Oct. 21, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-6827

    The DK ONLINE Beta (aka com.sgmobile.dkonline) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : dk_online_beta
    • Published: Sep. 30, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-6842

    The Daily Advertiser Print (aka com.lafayettedailyadv.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted c... Read more

    Affected Products : daily_advertiser_print
    • Published: Sep. 30, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-42054

    Cervantes through 0.5-alpha accepts insecure file uploads.... Read more

    Affected Products : cervantes
    • Published: Jul. 28, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4676

    The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : openstreetmap
    • Published: May. 30, 2023
    • Modified: Jan. 09, 2025
  • 5.4

    MEDIUM
    CVE-2014-6852

    The LedLine.gr Official (aka com.automon.ledline.gr) application 1.4.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : ledline.gr_official
    • Published: Oct. 01, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2022-4678

    The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more

    Affected Products : templatesnext_toolkit
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 5.4

    MEDIUM
    CVE-2023-37124

    A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more

    Affected Products : seacms
    • Published: Jul. 06, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-37132

    A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more

    Affected Products : eyoucms
    • Published: Jul. 06, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-42918

    itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO paramet... Read more

    • Published: Aug. 23, 2024
    • Modified: Mar. 13, 2025
  • 5.4

    MEDIUM
    CVE-2024-1590

    The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output esca... Read more

    Affected Products : pagelayer
    • Published: Feb. 23, 2024
    • Modified: Jan. 28, 2025
  • 5.4

    MEDIUM
    CVE-2024-4372

    The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks... Read more

    Affected Products : carousel_slider
    • Published: May. 21, 2024
    • Modified: Apr. 10, 2025
  • 5.4

    MEDIUM
    CVE-2023-42473

    S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application. ... Read more

    Affected Products : s\/4hana
    • Published: Oct. 10, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-2692

    A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name... Read more

    Affected Products : wedding_hall_booking_system
    • Published: Aug. 06, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-1972

    A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Employer/EditProfile.php. The manipulation of the argument Address leads to cross site scrip... Read more

    Affected Products : online_job_portal
    • Published: Feb. 28, 2024
    • Modified: Dec. 10, 2024
Showing 20 of 292871 Results