Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5529
The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : gameloft_library- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-16726
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.... Read more
Affected Products : razorcms- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5696
The Sonic 4 Episode II LITE (aka com.sega.sonic4ep2lite) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : sonic_4_episode_ii_lite- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5682
The Retale - Weekly Ads & Deals (aka com.retale.android) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : retale_-_weekly_ads_\&_deals- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1686
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5634
The Madipass Martinique (aka com.goodbarber.madipassmartinique) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : madipass_martinique- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5625
The Perfect Kick (aka com.gamegou.PerfectKick.google) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : perfect_kick- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5968
The iGolf - Golf GPS (aka com.igolf) application 20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : igolf_-_golf_gps- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5985
The Animal Kaiser Zangetsu (aka com.wAnimalKaiserZangetsu) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : animal_kaiser_zangetsu- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1692
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading... Read more
Affected Products : rational_quality_manager- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5894
The AireTalk: Text, Call, & More! (aka com.pingshow.amper) application 2.0.73 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : airetalk_text_call_\&_more\!- Published: Sep. 15, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-17090
An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing <textarea> followed by <script></script> tags.... Read more
Affected Products : donlinkage- Published: Sep. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-12184
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.... Read more
Affected Products : boostnote- Published: May. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19619
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.... Read more
Affected Products : mblog- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17184
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlement... Read more
Affected Products : syncope- Published: Nov. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3463
A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The manipulation of the argument karyawan leads to cross site scripting. The ... Read more
Affected Products : laundry_shop_management_system- Published: Apr. 08, 2024
- Modified: Jan. 14, 2025
-
5.4
MEDIUMCVE-2024-30989
Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.... Read more
Affected Products : client_management_system- Published: Apr. 17, 2024
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2023-33786
A stored cross-site scripting (XSS) vulnerability in the Create Circuit Types (/circuits/circuit-types/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-19918
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.... Read more
Affected Products : cuppacms- Published: Dec. 31, 2018
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2018-2397
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024