Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24601
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : wpfront_notification_bar- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1590
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads ... Read more
Affected Products : bludit- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25060
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscri... Read more
Affected Products : five_star_business_profile_and_schema- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31330
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.... Read more
Affected Products : review_board- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31792
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field... Read more
Affected Products : suitecrm- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26829
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.... Read more
Affected Products : scadabr- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-28424
A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.... Read more
Affected Products : teachers_record_management_system- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5004
EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site S... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2011-4019
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 a... Read more
- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2021-29388
A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Title'.... Read more
Affected Products : budget_management_system- Published: Apr. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29250
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.... Read more
Affected Products : btcpay_server- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-35475
SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.... Read more
Affected Products : environment_manager- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3012
A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remote authenticated users to inject arbitrary JavaScript code via a malicious HTML attribute such as onerror (in the URL field of the Param... Read more
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-22944
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrar... Read more
Affected Products : workspace_one_boxer- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24127
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into the project title (app_title) fiel... Read more
Affected Products : redcap- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24339
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.... Read more
Affected Products : teamcity- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37743
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.... Read more
Affected Products : misp- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3159
A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file.... Read more
Affected Products : landray_ekp- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24586
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.... Read more
Affected Products : pluxml- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5257
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of the currently-logged on user.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025