Latest CVE Feed
-
5.4
MEDIUMCVE-2017-17832
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (th... Read more
Affected Products : monitoring_software- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-16628
panel/login in Kirby v2.5.12 allows XSS via a blog name.... Read more
Affected Products : kirby- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1793
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c... Read more
Affected Products : rational_quality_manager- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14272
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.... Read more
Affected Products : silverstripe- Published: Sep. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin mana... Read more
Affected Products : nagios_xi- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1507
IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : rational_doors_next_generation- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17574
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.... Read more
Affected Products : yapi- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14787
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.... Read more
Affected Products : newsletters- Published: Aug. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11343
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.... Read more
Affected Products : soundsgood- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7739
The Anahi A Adopter FR (aka com.wAnahiAAdopterFR) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : anahi_a_adopter_fr- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7744
The Musulmanin.com (aka com.wSalyafiyailimurdjiya) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : musulmanin.com- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1891
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : security_guardium- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18082
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.... Read more
Affected Products : bamboo- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7753
The Circa News (aka cir.ca) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : circa_news- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7763
The Listen up! mirucho (aka jp.ameba.kiiteyo.android) application 1.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : listen_up\!_mirucho- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7767
The A+ (aka cn.xrzcm) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : a\+- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-16289
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.... Read more
Affected Products : woody_ad_snippets- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-2883
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerabili... Read more
Affected Products : tririga_application_platform- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1999021
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to t... Read more
- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-20285
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php... Read more
Affected Products : zzcms- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024