Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2024-8444

    The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.... Read more

    Affected Products : download_manager
    • Published: Oct. 30, 2024
    • Modified: Apr. 10, 2025
  • 5.4

    MEDIUM
    CVE-2020-35275

    Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.... Read more

    Affected Products : coastercms
    • Published: Dec. 21, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-13068

    public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).... Read more

    Affected Products : grafana
    • Published: Jun. 30, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-31290

    A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.... Read more

    Affected Products : known
    • Published: Jul. 08, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-3790

    A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the function add of the component assets-manager. The manipulation of the argument title/description leads to cross site scripting. The attac... Read more

    Affected Products : boom_cms
    • Published: Jul. 20, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-48115

    SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.... Read more

    Affected Products : smartermail
    • Published: Dec. 21, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-48131

    An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • Published: Jan. 26, 2024
    • Modified: Jun. 17, 2025
  • 5.4

    MEDIUM
    CVE-2023-0034

    The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above ... Read more

    Affected Products : jetwidgets_for_elementor
    • Published: Feb. 13, 2023
    • Modified: Jan. 14, 2025
  • 5.4

    MEDIUM
    CVE-2022-27156

    Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.... Read more

    Affected Products : fuel_cms
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24268

    The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.... Read more

    Affected Products : jetwidgets_for_elementor
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0078

    The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users... Read more

    Affected Products : resume_builder
    • Published: Mar. 06, 2023
    • Modified: May. 05, 2025
  • 5.4

    MEDIUM
    CVE-2023-5891

    Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.... Read more

    Affected Products : pkp_web_application_library
    • Published: Nov. 01, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-31774

    IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering ... Read more

    Affected Products : datapower_gateway
    • Published: Aug. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-1142

    Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters... Read more

    Affected Products : appliance
    • Published: Mar. 28, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-3067

    Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.... Read more

    Affected Products : trilium
    • Published: Jun. 02, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-43714

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SKIP_CART_PAGE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's ... Read more

    Affected Products : oscommerce
    • Published: Sep. 30, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-43191

    SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comments, these malicious codes embedded in the HTML will be executed, and the user's browser will be controlled by the attacker, so as to ach... Read more

    Affected Products : springbootcms
    • Published: Sep. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-43297

    An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • Published: Oct. 02, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-3442

    A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vulnerability is to data confidential... Read more

    Affected Products : openshift_api_management
    • Published: Aug. 22, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0271

    The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perf... Read more

    Affected Products : wp_font_awesome
    • Published: Feb. 21, 2023
    • Modified: Mar. 14, 2025
Showing 20 of 292814 Results