Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-4864

    Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.... Read more

    Affected Products : froxlor
    • EPSS Score: %0.07
    • Published: Dec. 30, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4306

    The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permiss... Read more

    Affected Products : panda_pods_repeater_field
    • EPSS Score: %8.28
    • Published: Jan. 30, 2023
    • Modified: Mar. 27, 2025
  • 5.4

    MEDIUM
    CVE-2022-43144

    A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more

    Affected Products : canteen_management_system
    • EPSS Score: %0.94
    • Published: Nov. 08, 2022
    • Modified: May. 01, 2025
  • 5.4

    MEDIUM
    CVE-2020-18693

    Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.... Read more

    Affected Products : minewebcms
    • EPSS Score: %0.26
    • Published: Aug. 06, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43491

    Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.... Read more

    • EPSS Score: %0.08
    • Published: Nov. 08, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43499

    Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.... Read more

    Affected Products : shirasagi
    • EPSS Score: %0.29
    • Published: Dec. 05, 2022
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2022-4377

    A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross s... Read more

    Affected Products : s-cms
    • EPSS Score: %0.09
    • Published: Dec. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4381

    The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : popup_maker
    • EPSS Score: %0.14
    • Published: Jan. 02, 2023
    • Modified: Apr. 10, 2025
  • 5.4

    MEDIUM
    CVE-2020-14012

    scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.... Read more

    Affected Products : osticket
    • EPSS Score: %0.19
    • Published: Jun. 10, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43952

    An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-sit... Read more

    Affected Products : fortiadc
    • EPSS Score: %0.25
    • Published: Apr. 11, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-33751

    A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at /app/tag/controller/ApiAdminTagCategory.php.... Read more

    Affected Products : mipjz
    • EPSS Score: %0.08
    • Published: May. 25, 2023
    • Modified: Jan. 31, 2025
  • 5.4

    MEDIUM
    CVE-2022-4487

    The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more

    Affected Products : easy_accordion
    • EPSS Score: %0.14
    • Published: Jan. 16, 2023
    • Modified: Apr. 08, 2025
  • 5.4

    MEDIUM
    CVE-2022-44944

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or H... Read more

    Affected Products : rukovoditel
    • EPSS Score: %1.10
    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2022-44951

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTM... Read more

    Affected Products : rukovoditel
    • EPSS Score: %1.73
    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2022-44954

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Nam... Read more

    Affected Products : webtareas
    • EPSS Score: %0.08
    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2023-34439

    Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.... Read more

    Affected Products : pleasanter
    • EPSS Score: %0.49
    • Published: Dec. 06, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4958

    A vulnerability classified as problematic has been found in qkmc-rk redbbs 1.0. Affected is an unknown function of the component Post Handler. The manipulation of the argument title leads to cross site scripting. It is possible to launch the attack remote... Read more

    Affected Products : redbbs
    • EPSS Score: %0.14
    • Published: Jan. 11, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4601

    A vulnerability was found in Shoplazza LifeStyle 1.1. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/api/theme-edit/ of the component Shipping/Member Discount/Icon. The manipulation leads to cross site scri... Read more

    Affected Products : lifestyle
    • EPSS Score: %0.08
    • Published: Dec. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-5539

    The Michael Baker FCU (aka air.com.creditunionhomebanking.mb155) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce... Read more

    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-5543

    The Hidden Object - Alice Free (aka air.com.differencegames.hovisionsofalicefree) application 1.0.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informatio... Read more

    Affected Products : hidden_object_-_alice_free
    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
Showing 20 of 291058 Results