Latest CVE Feed
-
5.4
MEDIUMCVE-2021-35956
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location... Read more
- EPSS Score: %0.98
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36551
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %0.19
- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24957
DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object and use the XSS payload as the name. Any user that opens... Read more
Affected Products : eqms- EPSS Score: %0.19
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-5229
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on ... Read more
Affected Products : universal_plugin_manager- EPSS Score: %0.18
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-32539
Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows remote authenticated users to inject JavaScript and perform a stored XSS attack.... Read more
Affected Products : 101eip- EPSS Score: %0.12
- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25224
Proton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the application opens the site in the current frame allowing an attacker to host JavaScript code in the malicious link in order to trigger... Read more
Affected Products : proton- EPSS Score: %0.28
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25630
An authenticated user can embed malicious content with XSS into the admin group policy page.... Read more
Affected Products : messaging_gateway- EPSS Score: %2.08
- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2021-38997
IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct vari... Read more
Affected Products : api_connect- EPSS Score: %0.09
- Published: Dec. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3355
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.... Read more
Affected Products : lightcms- EPSS Score: %0.22
- Published: Feb. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33852
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Set... Read more
Affected Products : post_duplicator- EPSS Score: %0.28
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39473
Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.... Read more
Affected Products : hotelmanager- EPSS Score: %0.24
- Published: Nov. 04, 2022
- Modified: May. 02, 2025
-
5.4
MEDIUMCVE-2021-40310
OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter.... Read more
Affected Products : opensis- EPSS Score: %0.46
- Published: Sep. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-18029
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.... Read more
Affected Products : navigate_cms- EPSS Score: %0.19
- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41557
Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders... Read more
Affected Products : miles_rich_internet_application- EPSS Score: %0.44
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41658
Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page.... Read more
Affected Products : student_quarterly_grading_system- EPSS Score: %0.34
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37152
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.... Read more
Affected Products : nexus_repository_manager- EPSS Score: %3.22
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37375
Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached ... Read more
- EPSS Score: %0.05
- Published: Feb. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37788
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP re... Read more
Affected Products : testrail- EPSS Score: %0.24
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38113
In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.... Read more
Affected Products : openwebif- EPSS Score: %0.17
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38138
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned f... Read more
- EPSS Score: %0.35
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024