Latest CVE Feed
-
5.4
MEDIUMCVE-2021-30056
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.... Read more
Affected Products : knowage- EPSS Score: %0.21
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-10583
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insuff... Read more
Affected Products : popup_maker- Published: Dec. 12, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2021-28935
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.23
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6884
The Ford Credit Account Manager (aka com.fordcredit.accountmanager) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted... Read more
Affected Products : ford_credit_account_manager- EPSS Score: %0.04
- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6887
The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-37675
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the parameter "sectionContent" related to the functionality of adding notes to an uploaded file.... Read more
Affected Products : docubase- Published: Jun. 21, 2024
- Modified: Mar. 18, 2025
-
5.4
MEDIUMCVE-2022-25605
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.... Read more
Affected Products : wp-downloadmanager- EPSS Score: %0.18
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-32069
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info Extension: from 1.39 through 1.43.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-32071
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-37764
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2014-6899
The Jazeera Airways (aka com.winit.jazeeraairways) application 2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jazeera_airways- EPSS Score: %0.04
- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-11050
A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to ... Read more
Affected Products : hotel_broadband_operating_system- Published: Nov. 10, 2024
- Modified: Nov. 23, 2024
-
5.4
MEDIUMCVE-2022-43721
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions ... Read more
Affected Products : superset- EPSS Score: %0.18
- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2023-33287
A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to store and execute arbitrary JavaScript via a crafted payload injected into the tables.... Read more
Affected Products : inline_table_editing- EPSS Score: %0.10
- Published: May. 31, 2023
- Modified: Jan. 10, 2025
-
5.4
MEDIUMCVE-2014-6904
The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : safe_browser_-_the_web_filter- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-4401
A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier o... Read more
Affected Products : pallidlight_online_course_selection_system- EPSS Score: %0.06
- Published: Dec. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6936
The IDS 2013 (aka de.mobileeventguide.ids2013) application 1.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ids_2013- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-32335
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.... Read more
- Published: Apr. 18, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2014-6913
The Dive The World (aka com.paperton.wl.divetheworld) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dive_the_world- EPSS Score: %0.04
- Published: Oct. 04, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-3818
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input saniti... Read more
Affected Products : essential_blocks- Published: Apr. 19, 2024
- Modified: Jan. 21, 2025