Latest CVE Feed
-
5.4
MEDIUMCVE-2023-43710
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1][MODULE_SHIPPING_PERCENT_TEXT_TITLE]" parameter, potentially leading to unauthorized ex... Read more
Affected Products : oscommerce- EPSS Score: %0.12
- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43703
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "product_info[][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web... Read more
Affected Products : oscommerce- EPSS Score: %0.12
- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43724
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthor... Read more
Affected Products : oscommerce- EPSS Score: %0.10
- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38970
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.... Read more
Affected Products : badaso- EPSS Score: %0.30
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38991
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.... Read more
Affected Products : jeesite- EPSS Score: %0.04
- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43990
An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- EPSS Score: %0.08
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
5.4
MEDIUMCVE-2016-6550
The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : the_u- EPSS Score: %0.04
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-4732
A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/service. The manipulation of the argument name leads to cross site ... Read more
Affected Products : legal_case_management_system- Published: May. 14, 2024
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2021-41866
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.... Read more
Affected Products : mybb- EPSS Score: %0.28
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44276
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.... Read more
Affected Products : opnsense- EPSS Score: %0.20
- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50983
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name sect... Read more
Affected Products : flightpath- Published: Nov. 15, 2024
- Modified: Jul. 07, 2025
-
5.4
MEDIUMCVE-2023-44761
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.... Read more
- EPSS Score: %0.30
- Published: Oct. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-8780
Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script or HTML via a content section note.... Read more
Affected Products : jease- EPSS Score: %0.14
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24563
In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.... Read more
Affected Products : genixcms- EPSS Score: %0.46
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2121
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Carousel widget in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping on user supp... Read more
- Published: Mar. 27, 2024
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2024-52584
Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission.... Read more
Affected Products : autolab- Published: Nov. 18, 2024
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2024-52762
A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.... Read more
Affected Products : ganglia-web- Published: Nov. 19, 2024
- Modified: Nov. 29, 2024
-
5.4
MEDIUMCVE-2024-52944
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could r... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2023-40282
Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.... Read more
- EPSS Score: %0.13
- Published: Aug. 23, 2023
- Modified: Jul. 01, 2025
-
5.4
MEDIUMCVE-2014-8944
Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config install_name, intro_message, or new_file_content parameter.... Read more
Affected Products : lexiglot- EPSS Score: %0.21
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024