Latest CVE Feed
-
5.4
MEDIUMCVE-2022-4642
A vulnerability was found in tatoeba2. It has been classified as problematic. This affects an unknown part of the component Profile Name Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit h... Read more
Affected Products : tatoeba2- EPSS Score: %0.07
- Published: Dec. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-46401
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.... Read more
Affected Products : bm78_firmware bm83_firmware rn4870_firmware rn4871_firmware bm70_firmware bm71_firmware pic_lightblue_explorer_demo_firmware bm64_firmware bm77_firmware rn4678_firmware +14 more products- EPSS Score: %0.06
- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2022-4674
The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : ibtana- EPSS Score: %0.34
- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2022-4675
The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : mongoose_page_plugin- EPSS Score: %0.12
- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2023-0287
A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remot... Read more
Affected Products : favorites-web- EPSS Score: %0.12
- Published: Jan. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0370
The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfo... Read more
Affected Products : wpb_advanced_faq- EPSS Score: %0.12
- Published: Mar. 20, 2023
- Modified: Feb. 26, 2025
-
5.4
MEDIUMCVE-2023-0549
A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subjec... Read more
Affected Products : yaf.net- EPSS Score: %0.11
- Published: Jan. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42329
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.... Read more
Affected Products : xinhe_teaching_platform_system- EPSS Score: %0.15
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-47524
F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.... Read more
Affected Products : safe- EPSS Score: %0.22
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
5.4
MEDIUMCVE-2017-7422
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to by... Read more
- EPSS Score: %0.10
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-4757
The List Pages Shortcode WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting ... Read more
Affected Products : list_pages_shortcode- EPSS Score: %0.11
- Published: Feb. 27, 2023
- Modified: Mar. 10, 2025
-
5.4
MEDIUMCVE-2014-5593
The Christian Dating Cafe (aka com.christiancafe.mobile.android) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce... Read more
Affected Products : christian_dating_cafe- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-4783
The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more
Affected Products : youtube_channel_gallery- EPSS Score: %0.24
- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2022-4786
The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : video.js- EPSS Score: %0.12
- Published: Feb. 21, 2023
- Modified: Mar. 13, 2025
-
5.4
MEDIUMCVE-2023-0902
A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file process_order.php. The manipulation of the argument order leads to cross site scripting. It is pos... Read more
Affected Products : simple_food_ordering_system simple_food_ordering_system simple_food_ordering_system- EPSS Score: %0.70
- Published: Feb. 18, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1022
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on the wpmsGGSaveInformation function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subs... Read more
Affected Products : wp_meta_seo- EPSS Score: %0.09
- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34550
Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.... Read more
Affected Products : student_information_management_system- EPSS Score: %0.20
- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1572
A vulnerability has been found in DataGear up to 1.11.1 and classified as problematic. This vulnerability affects unknown code of the component Plugin Handler. The manipulation leads to cross site scripting. It is possible to launch the attack on the loca... Read more
Affected Products : datagear- EPSS Score: %0.06
- Published: Mar. 22, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1796
A vulnerability classified as problematic has been found in SourceCodester Employee Payslip Generator 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_position of the component Create News Handler. The manipulation of the argume... Read more
Affected Products : employee_payslip_generator_system- EPSS Score: %0.06
- Published: Apr. 02, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-5471
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.... Read more
Affected Products : gitlab- EPSS Score: %0.07
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024