Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5661
The Anger of Stick 3 (aka com.miniclip.angerofstick3) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : anger_of_stick_3- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5665
The Mzone Login (aka com.mr384.MzoneLogin) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
- EPSS Score: %0.04
- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-40205
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.... Read more
Affected Products : wpforo_forum- EPSS Score: %0.08
- Published: Nov. 08, 2022
- Modified: Feb. 20, 2025
-
5.4
MEDIUMCVE-2022-40215
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.... Read more
Affected Products : tabs- EPSS Score: %0.05
- Published: Sep. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2404
The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : better_comments- Published: Apr. 24, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5681
The XDA-Developers (aka com.quoord.tapatalkxda.activity) application 3.9.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : xda-developers- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-24569
The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable to the bypass, the application must use toolkit version... Read more
Affected Products : java_code_security_toolkit- EPSS Score: %0.23
- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5690
The Runtastic Timer (aka com.runtastic.android.timer) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : runtastic_timer- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5706
The SomNote - Journal/Memo (aka com.somcloud.somnote) application 2.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : somnote_-_journal\/memo- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5713
The Telly - Watch the good stuff (aka com.telly) application 2.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : telly-watch_the_good_stuff- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5720
The Bike Race Free - Top Free Game (aka com.topfreegames.bikeracefreeworld) application 4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a c... Read more
Affected Products : bike_race_free_-_top_free_game- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-5273
A vulnerability classified as problematic was found in SourceCodester Best Courier Management System 1.0. This vulnerability affects unknown code of the file manage_parcel_status.php. The manipulation of the argument id leads to cross site scripting. The ... Read more
- EPSS Score: %0.07
- Published: Sep. 29, 2023
- Modified: Dec. 23, 2024
-
5.4
MEDIUMCVE-2024-51494
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2022-40358
An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload.... Read more
Affected Products : ajaxplorer- EPSS Score: %0.13
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.4
MEDIUMCVE-2024-25369
A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.... Read more
Affected Products : fuel_cms- Published: Feb. 22, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2024-30041
Microsoft Bing Search Spoofing Vulnerability... Read more
Affected Products : bing_search- Published: May. 14, 2024
- Modified: Jan. 08, 2025
-
5.4
MEDIUMCVE-2014-5777
The icon wallpaper dressup-CocoPPa (aka jp.united.app.cocoppa) application 2.8.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : icon_wallpaper_dressup-cocoppa- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-9070
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.... Read more
- EPSS Score: %0.22
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-7688
The Home Improvement (aka com.whomeimprovementapp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : home_improvement- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5805
The Dating for everyone - Mamba! (aka ru.mamba.client) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dating_for_everyone_-_mamba\!- EPSS Score: %0.04
- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025