Latest CVE Feed
-
5.4
MEDIUMCVE-2024-37675
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the parameter "sectionContent" related to the functionality of adding notes to an uploaded file.... Read more
Affected Products : docubase- Published: Jun. 21, 2024
- Modified: Mar. 18, 2025
-
5.4
MEDIUMCVE-2022-25605
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.... Read more
Affected Products : wp-downloadmanager- EPSS Score: %0.18
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-32069
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info Extension: from 1.39 through 1.43.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-32071
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-37764
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2014-6899
The Jazeera Airways (aka com.winit.jazeeraairways) application 2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jazeera_airways- EPSS Score: %0.04
- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-11050
A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to ... Read more
Affected Products : hotel_broadband_operating_system- Published: Nov. 10, 2024
- Modified: Nov. 23, 2024
-
5.4
MEDIUMCVE-2022-43721
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions ... Read more
Affected Products : superset- EPSS Score: %0.18
- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2023-33287
A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to store and execute arbitrary JavaScript via a crafted payload injected into the tables.... Read more
Affected Products : inline_table_editing- EPSS Score: %0.10
- Published: May. 31, 2023
- Modified: Jan. 10, 2025
-
5.4
MEDIUMCVE-2014-6904
The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : safe_browser_-_the_web_filter- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-4401
A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier o... Read more
Affected Products : pallidlight_online_course_selection_system- EPSS Score: %0.06
- Published: Dec. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6936
The IDS 2013 (aka de.mobileeventguide.ids2013) application 1.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ids_2013- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-32335
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.... Read more
- Published: Apr. 18, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2014-6913
The Dive The World (aka com.paperton.wl.divetheworld) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dive_the_world- EPSS Score: %0.04
- Published: Oct. 04, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-3818
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input saniti... Read more
Affected Products : essential_blocks- Published: Apr. 19, 2024
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2014-6940
The Absolute Lending Solutions (aka com.soln.S008F6C05EC0B63264B429F6D76286562) application 1.0073.b0073 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inform... Read more
Affected Products : absolute_lending_solutions- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6942
The Alisha Marie (Unofficial) (aka com.automon.ay.alisha.marie) application 1.4.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted c... Read more
Affected Products : alisha_marie- EPSS Score: %0.04
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-38626
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ... Read more
Affected Products : apex_central- EPSS Score: %0.15
- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2014-6970
The North American Ismaili Games (aka hr.apps.n166983741) application 5.26.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific... Read more
Affected Products : north_american_ismaili_games- EPSS Score: %0.04
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6973
The Care4Kids (aka com.codetherapy.care4kids) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : care4kids- EPSS Score: %0.04
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025