Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5975
The eponyms (aka com.anddeveloper.eponyms) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : eponyms- EPSS Score: %0.04
- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-33588
Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. ... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-28795
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
Affected Products : infosphere_information_server- Published: Jun. 30, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-26490
A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.... Read more
Affected Products : flusity- Published: Feb. 22, 2024
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2024-56234
Missing Authorization vulnerability in VW THEMES VW Automobile Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through 2.1.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
5.4
MEDIUMCVE-2024-28965
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, ... Read more
Affected Products : secure_connect_gateway- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2997
A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Na... Read more
- Published: Mar. 27, 2024
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2014-5980
The Genertel (aka com.genertel) application 2.6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : genertel- EPSS Score: %0.04
- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5987
The My3 - by 3HK (aka com.my3) application @7F0A0001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : my3- EPSS Score: %0.04
- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-25608
Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action.... Read more
Affected Products : yoo_slider- EPSS Score: %0.12
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35561
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.... Read more
- Published: May. 22, 2024
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2014-6003
The Belas Frases de Amor (aka com.goodbarber.frasesdeamor) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : belas_frases_de_amor- EPSS Score: %0.04
- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6013
The nuSquare (aka tw.com.nuphoto.nusquare) application 1.0.78 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : nusquare- EPSS Score: %0.04
- Published: Sep. 22, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-25611
Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].... Read more
Affected Products : simple_event_planner- EPSS Score: %0.17
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3570
A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user's session. By manipulating the ChatBot responses, ... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2024-31369
Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. ... Read more
Affected Products : soledad- Published: Apr. 09, 2024
- Modified: Jul. 02, 2025
-
5.4
MEDIUMCVE-2024-31403
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.... Read more
Affected Products : garoon- Published: Jun. 11, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2017-9331
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted meet... Read more
Affected Products : epesi- EPSS Score: %0.16
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-28499
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.... Read more
Affected Products : slide_anything-responsive_content\/html_slider_and_carousel- EPSS Score: %0.22
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3695
A vulnerability has been found in SourceCodester Computer Laboratory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php. The manipulation of the argument id leads to cross site scrip... Read more
- Published: Apr. 12, 2024
- Modified: Jan. 21, 2025