Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2014-5627

    The Ice Age Village (aka com.gameloft.android.ANMP.GloftIAHM) application 2.8.0m for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more

    Affected Products : ice_age_village
    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2017-1000465

    Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.... Read more

    Affected Products : sulu sulu-standard
    • EPSS Score: %0.32
    • Published: Jan. 09, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-5649

    The iLove - Free Dating & Chat App (aka com.jestadigital.android.ilove) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cra... Read more

    Affected Products : ilove_-_free_dating_\&_chat_app
    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2021-20112

    A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could uplo... Read more

    Affected Products : tcexam
    • EPSS Score: %0.21
    • Published: Jul. 30, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-27308

    A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a project title.... Read more

    Affected Products : phprojekt_phpsimplygest
    • EPSS Score: %0.53
    • Published: May. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2019-15614

    Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.... Read more

    Affected Products : nextcloud
    • EPSS Score: %0.25
    • Published: Feb. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-48642

    Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. Whe... Read more

    Affected Products : archer
    • EPSS Score: %0.21
    • Published: Dec. 12, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-21845

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more

    Affected Products : peoplesoft_enterprise_peopletools
    • EPSS Score: %0.22
    • Published: Jan. 18, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-5580

    The BackgroundCheckProTool (aka com.BackgroundCheckProTool) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifica... Read more

    Affected Products : backgroundcheckprotool
    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-5723

    The Trapster (aka com.trapster.android) application 4.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : trapster
    • EPSS Score: %0.04
    • Published: Sep. 09, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-6639

    The TIO MobilePay - Bill Payments (aka com.tionetworks.mobile.android.tioclient) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information ... Read more

    Affected Products : tio_mobilepay_-_bill_payments
    • EPSS Score: %0.04
    • Published: Sep. 22, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-6939

    The Sketch W Friends FREE -Tablets (aka air.com.xlabz.SketchWFriendsFree) application 5.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a c... Read more

    Affected Products : sketch_w_friends_free_-tablets
    • EPSS Score: %0.04
    • Published: Oct. 11, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7002

    The Sopexa Pavillon France (aka com.goomeoevents.pavillonfrance) application 3.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce... Read more

    Affected Products : sopexa_pavillon_france
    • EPSS Score: %0.04
    • Published: Oct. 16, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7086

    The Killer Screen lock (aka com.cc.theme.shashou) application 0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : killer_screen_lock
    • EPSS Score: %0.04
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-6933

    The Toraware Takojyou (aka ltd.pte.wavea.torawaretakojyou) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more

    Affected Products : toraware_takojyou
    • EPSS Score: %0.04
    • Published: Oct. 04, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7360

    The How To Boil Eggs (aka com.appmakr.app842173) application 251333 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : how_to_boil_eggs
    • EPSS Score: %0.04
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2014-7078

    The Payoneer Sign Up (aka com.wPayoneerSignUp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : payoneer_sign_up
    • EPSS Score: %0.04
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2020-15020

    An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.... Read more

    Affected Products : website_builder
    • EPSS Score: %0.15
    • Published: Aug. 31, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-15029

    NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.... Read more

    Affected Products : nedi
    • EPSS Score: %0.34
    • Published: Jul. 07, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-7089

    The COMPETITION INFORMATION (aka com.ear.bilgiyarismasi) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : competition_information
    • EPSS Score: %0.04
    • Published: Oct. 19, 2014
    • Modified: Apr. 12, 2025
Showing 20 of 291601 Results