Latest CVE Feed
-
5.4
MEDIUMCVE-2021-46146
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.... Read more
Affected Products : mediawiki- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36948
In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.... Read more
Affected Products : netbackup- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-52059
A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.... Read more
Affected Products : gestsup- Published: Feb. 13, 2024
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2023-6142
Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.... Read more
Affected Products : dev_blog- Published: Nov. 21, 2023
- Modified: May. 19, 2025
-
5.4
MEDIUMCVE-2023-30959
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.... Read more
Affected Products : apollo_autopilot- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-6485
The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stor... Read more
Affected Products : html5_video_player- Published: Jan. 01, 2024
- Modified: Jun. 18, 2025
-
5.4
MEDIUMCVE-2014-4897
The Touriosity Travelmag (aka com.magzter.touriositytravelmag) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : touriosity_travelmag- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-3730
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escapin... Read more
Affected Products : simple_membership- Published: Apr. 25, 2024
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2024-38351
Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order to be exploited users must have both OAuth2 and Password auth methods enabled. A possible attack scenario... Read more
Affected Products :- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-0346
A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of the component Feedback Page. The manipulation of the argument My Testem... Read more
Affected Products : vehicle_booking_system- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-37407
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.... Read more
Affected Products : gallery_photoblocks- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-38737
Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422.... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2024-1746
The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : testimonial_slider_and_showcase- Published: Apr. 15, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2024-41587
Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2763_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware +38 more products- Published: Oct. 03, 2024
- Modified: Mar. 18, 2025
-
5.4
MEDIUMCVE-2024-4176
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sendi... Read more
Affected Products : xconsole- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25059
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of th... Read more
Affected Products : download_plugin- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2014-6962
The Elk Grove PublicStuff (aka com.wassabi.elkgrove) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : elk_grove_publicstuff- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-2089
The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products : remote_content_shortcode- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-4270
The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.... Read more
Affected Products : svgmagic- Published: Jun. 14, 2024
- Modified: Mar. 24, 2025
-
5.4
MEDIUMCVE-2014-7091
The Sacramento Kings (aka com.tibco.gse.sports) application 6.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : sacramento_kings- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025