Latest CVE Feed
-
5.4
MEDIUMCVE-2020-4419
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : jazz_reporting_service- Published: May. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6981
The Taiwan Business Bank (aka com.mitake.TBB) application 2.04 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : taiwan_business_bank- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6985
The Georgia Packing (aka com.tapatalk.georgiapackingorg) application 3.9.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifica... Read more
Affected Products : georgia_packing- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-11678
A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. The manipulation of the argument pat_fname/pat_ailme... Read more
Affected Products : hospital_management_system- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2014-7034
The Senator Inn & Spa (aka com.conduit.app_cc06e8e9659c4cf7b361ad0b7717f3a4.app) application 1.2.2.160 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat... Read more
Affected Products : senator_inn_\&_spa- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-3427
The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on the 'save_customer' function. This makes it possible for unauthentic... Read more
Affected Products : salon_booking_system- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-38971
vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.... Read more
Affected Products : vaethink- Published: Jul. 09, 2024
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-4469
The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more
Affected Products : simple_membership- Published: Jan. 16, 2023
- Modified: Apr. 08, 2025
-
5.4
MEDIUMCVE-2014-7055
The NCCI's Annual Issues Symposium (aka com.quickmobile.ais14) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : ncci\'s_annual_issues_symposium- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-4482
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored C... Read more
Affected Products : carousel\,_slider\,_gallery_by_wp_carousel- Published: Jan. 16, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2023-34412
A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).... Read more
- Published: Aug. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4491
The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting... Read more
Affected Products : wp-table_reloaded- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2014-7101
The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifica... Read more
Affected Products : talk_radio_europe- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-44956
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name fie... Read more
Affected Products : webtareas- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2025-5974
A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this issue is some unknown functionality of the file /check-status.php. The manipulation of the argument searchdata leads t... Read more
Affected Products : restaurant_table_booking_system- Published: Jun. 10, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2014-7118
The Itography Item Hunt (aka com.itography.application) application 3.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
Affected Products : itography_item_hunt- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7127
The Football Espana magazine (aka com.triactivemedia.footballespana) application @7F0801AA for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr... Read more
Affected Products : football_espana_magazine- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7128
The Toyota OC (aka com.tapatalk.toyotaownersclubcomforums) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific... Read more
Affected Products : toyota_oc- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-29673
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ... Read more
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-6870
The BGEnergy (aka com.bluegrass.smartapps) application 1.153.0034 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : bgenergy- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025