Latest CVE Feed
-
5.4
MEDIUMCVE-2023-32669
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).... Read more
Affected Products : buddyboss- EPSS Score: %0.05
- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6892
The kalahari.com Shopping (aka com.kalahari.shop) application 1.4.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : kalahari.com_shopping- EPSS Score: %0.04
- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-3319
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iDisplay PlatPlay DS allows Stored XSS.This issue affects PlatPlay DS: before 3.14. ... Read more
Affected Products : platplay_ds- EPSS Score: %0.10
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-3965
A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The... Read more
Affected Products : paicoding- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2020-4252
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.16
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43980
There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clic... Read more
Affected Products : pandora_fms- EPSS Score: %0.20
- Published: Jan. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-39522
Missing Authorization vulnerability in Sebastian Lee Dynamic Post allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Dynamic Post: from n/a through 4.10.... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2022-44012
An issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferantenmanager before 5.6. An attacker can execute JavaScript code in the browser of the victim if a site is loaded. The victim's encrypted pa... Read more
Affected Products : lieferantenmanager- EPSS Score: %0.14
- Published: Dec. 25, 2022
- Modified: Apr. 15, 2025
-
5.4
MEDIUMCVE-2023-33793
A stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- EPSS Score: %0.08
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33798
A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- EPSS Score: %0.08
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-47201
In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaScript code in HTML, aka XSS.... Read more
Affected Products : intrexx- Published: May. 02, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-47473
Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2014-6938
The Apostilas musicais (aka com.apostilas) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : apostilas_musicais- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6919
The Metalcasting Newsstand (aka air.com.yudu.ReaderAIR3017071) application 3.12.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer... Read more
Affected Products : metalcasting_newsstand- EPSS Score: %0.04
- Published: Oct. 04, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6952
The Manga Facts (aka app.mangafacts.ar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : manga_facts- EPSS Score: %0.04
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6956
The Hydrogen Water (aka com.appzone628) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : hydrogen_water- EPSS Score: %0.04
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6964
The Hanyang University Admissions (aka kr.ac.hanyang.planner) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : hanyang_university_admissions- EPSS Score: %0.04
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-4419
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.18
- Published: May. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6981
The Taiwan Business Bank (aka com.mitake.TBB) application 2.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : taiwan_business_bank- EPSS Score: %0.04
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6985
The Georgia Packing (aka com.tapatalk.georgiapackingorg) application 3.9.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifica... Read more
Affected Products : georgia_packing- EPSS Score: %0.04
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025