Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2019-7881

    A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).... Read more

    Affected Products : magento
    • EPSS Score: %0.10
    • Published: Aug. 02, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-28647

    In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the co... Read more

    Affected Products : moveit_transfer
    • EPSS Score: %0.08
    • Published: Nov. 17, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-8138

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by s... Read more

    Affected Products : magento
    • EPSS Score: %0.18
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-8439

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.... Read more

    Affected Products : dilicms
    • EPSS Score: %0.21
    • Published: Mar. 07, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-20575

    An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).... Read more

    Affected Products : android
    • EPSS Score: %0.02
    • Published: Mar. 24, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-36553

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.... Read more

    • EPSS Score: %0.34
    • Published: Jul. 15, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-4303

    IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more

    • EPSS Score: %0.23
    • Published: Jun. 19, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-4409

    HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name retu... Read more

    Affected Products : traveler
    • EPSS Score: %0.32
    • Published: Oct. 18, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-3997

    VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.... Read more

    Affected Products : horizon
    • EPSS Score: %0.23
    • Published: Oct. 23, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4268

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more

    • EPSS Score: %0.24
    • Published: Apr. 15, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-4645

    IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more

    • EPSS Score: %0.24
    • Published: Jul. 29, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5186

    DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).... Read more

    Affected Products : dotnetnuke dotnetnuke
    • EPSS Score: %0.35
    • Published: Feb. 24, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5747

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.... Read more

    Affected Products : tcexam
    • EPSS Score: %0.16
    • Published: May. 07, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-14388

    joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.... Read more

    Affected Products : joyplus-cms
    • EPSS Score: %0.15
    • Published: Jul. 18, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-6854

    A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from the REST API.... Read more

    Affected Products : jobscheduler
    • EPSS Score: %0.37
    • Published: Feb. 05, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-0280

    Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glos... Read more

    • EPSS Score: %0.15
    • Published: Aug. 08, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2019-9556

    FiberHome an5506-04-f RP2669 devices have XSS.... Read more

    Affected Products : an5506-04-f_firmware an5506-04-f
    • EPSS Score: %0.50
    • Published: Dec. 31, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-8777

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.... Read more

    Affected Products : alfresco
    • EPSS Score: %0.73
    • Published: Mar. 02, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-14959

    Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, I... Read more

    Affected Products : easy_testimonials
    • EPSS Score: %0.16
    • Published: Jun. 22, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-9008

    Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.... Read more

    Affected Products : blackboard_learn
    • EPSS Score: %0.18
    • Published: Feb. 25, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 292386 Results