Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2014-8944

    Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config install_name, intro_message, or new_file_content parameter.... Read more

    Affected Products : lexiglot
    • EPSS Score: %0.21
    • Published: Jun. 01, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-27991

    Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).... Read more

    Affected Products : nagios_xi
    • EPSS Score: %17.74
    • Published: Nov. 16, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-45806

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able... Read more

    Affected Products : discourse
    • EPSS Score: %2.60
    • Published: Nov. 10, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10051

    iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.... Read more

    Affected Products : supportdesk
    • EPSS Score: %0.28
    • Published: Apr. 11, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-40705

    Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.... Read more

    Affected Products : video_insight
    • EPSS Score: %0.09
    • Published: Sep. 05, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-45998

    kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.... Read more

    Affected Products : kodbox
    • EPSS Score: %0.16
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-33910

    An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of dow... Read more

    Affected Products : mantisbt
    • EPSS Score: %0.25
    • Published: Jun. 24, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4673

    The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : rate_my_post
    • EPSS Score: %0.11
    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-4479

    The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting... Read more

    Affected Products : table_of_contents_plus
    • EPSS Score: %0.14
    • Published: Jan. 09, 2023
    • Modified: Apr. 09, 2025
  • 5.4

    MEDIUM
    CVE-2023-4811

    The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.... Read more

    Affected Products : wordpress_file_upload
    • EPSS Score: %0.10
    • Published: Oct. 16, 2023
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2024-23941

    Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the prod... Read more

    Affected Products : group_office
    • EPSS Score: %0.10
    • Published: Feb. 01, 2024
    • Modified: Jun. 04, 2025
  • 5.4

    MEDIUM
    CVE-2018-10164

    Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload fun... Read more

    Affected Products : eap_controller
    • EPSS Score: %0.30
    • Published: May. 03, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10206

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field of a file request.... Read more

    Affected Products : enterprise_file_sharing
    • EPSS Score: %0.21
    • Published: Apr. 25, 2018
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-41168

    NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).... Read more

    Affected Products : ngeniusone
    • EPSS Score: %0.57
    • Published: Dec. 07, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-5627

    The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.... Read more

    Affected Products : tournamatch
    • Published: Jul. 13, 2024
    • Modified: May. 13, 2025
  • 5.4

    MEDIUM
    CVE-2021-3258

    Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution.... Read more

    Affected Products : q2a_ultimate_seo
    • EPSS Score: %0.52
    • Published: Feb. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10250

    iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.... Read more

    Affected Products : icms
    • EPSS Score: %0.21
    • Published: Apr. 20, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-29215

    A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.... Read more

    Affected Products : employee_management_system
    • EPSS Score: %0.16
    • Published: Jun. 15, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-55651

    i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuári... Read more

    Affected Products : i-educar
    • Published: May. 08, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2018-10364

    BigTree before 4.2.22 has XSS in the Users management page via the name or company field.... Read more

    Affected Products : bigtree_cms
    • EPSS Score: %0.23
    • Published: Apr. 30, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291368 Results