Latest CVE Feed
-
5.4
MEDIUMCVE-2014-7719
The BASEBALL MANAGER K (aka com.cjenm.yagamkgoogle) application 1.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : baseball_manager_k- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7715
The GIGA HOBBY (aka com.innopage.store.gigahobby) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : giga_hobby- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-20349
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.... Read more
Affected Products : wtcms- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1657
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- Published: Jan. 04, 2019
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2014-5529
The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : gameloft_library- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-16726
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.... Read more
Affected Products : razorcms- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5696
The Sonic 4 Episode II LITE (aka com.sega.sonic4ep2lite) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : sonic_4_episode_ii_lite- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5682
The Retale - Weekly Ads & Deals (aka com.retale.android) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : retale_-_weekly_ads_\&_deals- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1686
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5634
The Madipass Martinique (aka com.goodbarber.madipassmartinique) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : madipass_martinique- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5625
The Perfect Kick (aka com.gamegou.PerfectKick.google) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : perfect_kick- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5968
The iGolf - Golf GPS (aka com.igolf) application 20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : igolf_-_golf_gps- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5985
The Animal Kaiser Zangetsu (aka com.wAnimalKaiserZangetsu) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : animal_kaiser_zangetsu- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-1692
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading... Read more
Affected Products : rational_quality_manager- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5894
The AireTalk: Text, Call, & More! (aka com.pingshow.amper) application 2.0.73 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : airetalk_text_call_\&_more\!- Published: Sep. 15, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2018-17090
An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing <textarea> followed by <script></script> tags.... Read more
Affected Products : donlinkage- Published: Sep. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-12184
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.... Read more
Affected Products : boostnote- Published: May. 19, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19619
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.... Read more
Affected Products : mblog- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17184
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlement... Read more
Affected Products : syncope- Published: Nov. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3463
A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The manipulation of the argument karyawan leads to cross site scripting. The ... Read more
Affected Products : laundry_shop_management_system- Published: Apr. 08, 2024
- Modified: Jan. 14, 2025