Latest CVE Feed
-
5.4
MEDIUMCVE-2024-32797
Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11.... Read more
Affected Products :- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29105
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.... Read more
Affected Products : arcgis_server- Published: Jul. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3850
Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can ... Read more
- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-52179
Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.... Read more
Affected Products : product_expiry_for_woocommerce- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20363
IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
Affected Products : cloud_pak_for_applications- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-52183
Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.... Read more
Affected Products : backup_and_migration- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33682
SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with basic level privileges to store a malicious script on SAP Lumira Server. The execut... Read more
Affected Products : lumira_server- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-5553
The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, 4.10.33 due to insufficient input sanitization and output escaping. This makes it pos... Read more
Affected Products : premium_addons_for_elementor- Published: Jun. 12, 2024
- Modified: Jan. 15, 2025
-
5.4
MEDIUMCVE-2023-38395
Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.... Read more
Affected Products : wp_clone_menu- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-1766
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more
- Published: Jun. 12, 2024
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2024-37297
WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not... Read more
Affected Products : woocommerce- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36747
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.... Read more
Affected Products : blackboard_learn- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-22722
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8... Read more
Affected Products : evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_ev.2_firmware evlink_smart_wallbox_evb1a_firmware evlink_city_evc1s22p4 evlink_city_evc1s7p4 evlink_parking_evw2 evlink_parking_evf2 +2 more products- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37451
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).... Read more
Affected Products : ivm_attendant- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37463
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).... Read more
Affected Products : quorum- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37466
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).... Read more
Affected Products : quorum- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23238
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.... Read more
Affected Products : evolution_cms- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36605
engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be executed in the user's browser.... Read more
Affected Products : engineercms- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35591
An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.... Read more
Affected Products : o2oa- Published: May. 24, 2024
- Modified: Nov. 21, 2024