Latest CVE Feed
-
5.4
MEDIUMCVE-2022-25929
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these p... Read more
Affected Products : smoothie_charts- Published: Dec. 21, 2022
- Modified: Apr. 16, 2025
-
5.4
MEDIUMCVE-2022-27110
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.... Read more
Affected Products : orangehrm- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40100
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.... Read more
Affected Products : concrete_cms- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-27854
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter.... Read more
Affected Products : psychological_tests_\&_quizzes- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1824
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29439
Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting slides.... Read more
Affected Products : image_slider_by_nextcode- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-30057
Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.... Read more
Affected Products : shopwind- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29975
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .... Read more
Affected Products : mdaemon- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43462
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.... Read more
Affected Products : rumble_mail_server- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43505
Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.... Read more
Affected Products : simple_client_management_system- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43712
Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.... Read more
Affected Products : employee_daily_task_management_system- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19046
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.... Read more
Affected Products : s-cms- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44211
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.... Read more
Affected Products : ox_app_suite- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-6226
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems.... Read more
Affected Products : email_encryption_gateway- Published: Mar. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-6227
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems.... Read more
Affected Products : email_encryption_gateway- Published: Mar. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5763
The Kid Mode: Free Games + Lock (aka com.zoodles.kidmode) application 4.9.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifica... Read more
Affected Products : kid_mode\- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-19289
A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.... Read more
Affected Products : jeesns- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5798
The smart.calculator (aka nh.smart.calculator) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : smart_calculator- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-4139
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
Affected Products : cognos_analytics- Published: May. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4136
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : cognos_controller- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024